Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Enable Clickjack Protection for Visualforce Pages

Enable Clickjack Protection for Visualforce Pages

To help protect against clickjack attacks, prevent external sites from loading your Visualforce pages in an inline frame (iframe). Optionally, you can allow trusted external sites to frame your Visualforce pages.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: Contact Manager, Group, Professional, Enterprise, Performance, Unlimited, and Developer Editions
User Permissions Needed
To modify session security settings: Customize Application
  1. Allowlist domains that currently frame your Visualforce pages.

    To preserve existing functionality, complete this steps before you enable clickjack protection for Visualforce pages.

    Add each domain that you trust to the Trusted Domains for Inline Frames allowlist in Session Settings. If you use custom domains or managed packages, include those domains in the allowlist as well. For more information, see Specify Trusted Domains for Inline Frames in Salesforce Help.

    Note
    Note Some infrastructure limits the maximum size of HTTP headers. If you allow multiple domains to frame your Visualforce pages, keep the size of the CSP header under 12 KB. Salesforce customers report issues when the header size approaches 16 KB, and third parties often add to the header during processing.
  2. From Setup, use the Quick Find box to find and select Session Settings.

    The two settings under Clickjack Protection for Visualforce pages refer to whether headers are enabled. The apex:page field showHeader indicates whether headers are enabled on a page.

  3. To allow other Visualforce pages to frame Visualforce pages with headers enabled, select Enable clickjack protection for customer Visualforce pages with standard headers.
  4. To allow other Visualforce pages to frame Visualforce pages with headers disabled, select Enable clickjack protection for customer Visualforce pages with headers disabled.
  5. Save your changes.
    When you save your session settings with at least one of the options enabled, the CSP frame-ancestors HTTP response header for the corresponding Visualforce pages is set to 'self'. And any trusted domains for inline frames for Visualforce pages included in the same HTTPS response header.
 
Loading
Salesforce Help | Article