Hi @Zanar
I’d be happy to share some more information on this topic with you and let you know what the options are moving forward. This option is enabled by default for all online stores as a preventative measure to protect from clickjacking attacks on the store.
You can request this is disabled through our authenticated support channels (Shopify Help Center), but before doing so please review the information I shared below. If you accept these risks then feel free to make this request to our support team through the Help Center.
- Disabling protection can only be done in relation to the storefront. It’s not possible to disable this in order to access the admin OR our checkout inside an iFrame.
- The setting is either fully ON or fully OFF. There’s no way to have a ‘blocked’ or ‘unblocked’ list for iFrame access for a storefront.
- Disabling this protection could allow Clickjacking attacks from hackers, which would be difficult to prevent or detect once the setting has been turned off. The risks include things like User Interface Redress Attacks where users are tricked into unintended actions, and Phishing and Social Engineering Attacks that deceive users into providing sensitive information. It can also lead to Unauthorized Actions performed without user consent, resulting in unwanted changes or purchases. Furthermore, disabling protection may cause a Loss of Trust and Reputation among users, negatively impacting your brand, and create Legal and Compliance Issues by violating security standards and regulations. It’s crucial to consider these risks before making a decision about clickjacking protection.