SAP Knowledge Base Article - Preview

3334671 - Response Header set X-Frame-Options to Deny

Symptom

When embedding a JS Storefront endpoint from SAP Commerce Cloud into other 3rd party web application, the JS Storefront would not be displayed correctly. In the console tab of the browser, an error similar to below one can be seen:

In certain features, such as SmartEdit, a blank page can also be seen with similar error as the following one:

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."


Read more...

Environment

  • SAP Commerce Cloud
  • SAP Commerce Cloud, Composable Storefront

Product

SAP Commerce Cloud all versions ; SAP Commerce Cloud, composable storefront all versions

Keywords

X-Frame-Options, Spartacus, endpoint, cross-domain, iFrame, CORS, SmartEdit, refused to connect, sedit, composable , KBA , CEC-SPA , SAP Commerce Cloud Spartacus , CEC-SCC-COM-SEDIT , SmartEdit , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.