Shopify App review
Budget: €250 – €750 EUR
Hey Guys,
we developed a shopify app. but in the review we get everytime rejected. But we have no clue why.
so we need someone who can review our code with us together and help us to solve the problems. here the error message:
App must set security headers to protect against clickjacking.
To prevent clickjacking attacks, your app must set the proper content security policy directive. If your app is not embedded in an Iframe in the Shopify admin, and you are seeing this message, check your app's settings and make sure it is set to "non-embedded." If your app is embedded, then we expect the 'Content-Security-Policy' header to be frame-ancestorshttps://admin.shopify.comhttps://[shop].myshopify.com, where [shop] is dynamically set to the shop domain the app is embedded on. App must verify the authenticity of the request from Shopify.
Your app's HTTPS webhook endpoints must validate the HMAC digest of each request, and return an HTTP 401 (Unauthorized) response code when rejecting a request that has an invalid digest. Learn more about securing mandatory GDPR webhooks
What Does This Mean?: An email conversation is only started with an App Review Specialist when all the requirements in this email are met. Please follow the instructions at the top of this email to proceed.
Our DevStack is Angular and Nestjs so you should have good experience with that.
we developed a shopify app. but in the review we get everytime rejected. But we have no clue why.
so we need someone who can review our code with us together and help us to solve the problems. here the error message:
App must set security headers to protect against clickjacking.
To prevent clickjacking attacks, your app must set the proper content security policy directive. If your app is not embedded in an Iframe in the Shopify admin, and you are seeing this message, check your app's settings and make sure it is set to "non-embedded." If your app is embedded, then we expect the 'Content-Security-Policy' header to be frame-ancestorshttps://admin.shopify.comhttps://[shop].myshopify.com, where [shop] is dynamically set to the shop domain the app is embedded on. App must verify the authenticity of the request from Shopify.
Your app's HTTPS webhook endpoints must validate the HMAC digest of each request, and return an HTTP 401 (Unauthorized) response code when rejecting a request that has an invalid digest. Learn more about securing mandatory GDPR webhooks
What Does This Mean?: An email conversation is only started with an App Review Specialist when all the requirements in this email are met. Please follow the instructions at the top of this email to proceed.
Our DevStack is Angular and Nestjs so you should have good experience with that.