cancel
Showing results for 
Search instead for 
Did you mean: 

X-Frame-Options on storefront set to DENY on Hybris 6.2

Former Member
0 Kudos

The X-Frame-Options on store front response is set to DENY although in project.properties its set to SAMEORIGIN, due to this the iframe doesnt render in another window and preview/live edit is not working on cmscockpit and smart edit.

setting 'X-Frame-Options=SAMEORIGIN' to prevent clickjacking attacks

ss.filter.header.X-Frame-Options=SAMEORIGIN

Accepted Solutions (0)

Answers (1)

Answers (1)

tsang
Explorer
0 Kudos

Hi Rubal,

in case u havent fixed this issue. I have found a solution for me. See

https://answers.sap.com/questions/12765164/x-frame-options-headers-with-conflicting-values-sa.html?c...