사용자를 클릭잭 공격으로부터 보호하기 위해 Salesforce는 지시문이 지원되는 경우 Salesforce에서 제공하는 페이지에 CSP(콘텐츠 보안 정책): frame-ancestors HTTP 헤더 지시문을 적용합니다. 더 많은 사용자를 위해 클릭잭 방어를 확대하려면 Salesforce에서 요청 앱 또는 전문 브라우저에서 지시문을 지원하는지를 식별할 수 없는 드문 사례에 해당 지시문을 포함합니다.
필수 Edition
지원 제품: Salesforce Classic 및 Lightning Experience 모두
Salesforce Lightning Experience 및 Salesforce Classic의 지원되는 브라우저와 장치는 클릭잭 방어에 필요한 HTTP 헤더 지시문을 지원합니다. 사용자가 지원되지 않는 앱 또는 CSP(콘텐츠 보안 정책): frame-ancestors HTTP에 대한 지원이 명확하지 않은 전문 브라우저를 통해 Salesforce에 액세스하는 경우에만 이 기능을 활성화하는 것이 좋습니다.
경고 이 옵션을 활성화하면 CSP(콘텐츠 보안 정책): frame-ancestors 지시문이 지원되지 않는 앱 또는 브라우저를 통해 Salesforce에 액세스하는 사용자에게 지원이 없을 때 오류가 발생할 수 있습니다. 사용자의 앱 및 브라우저를 통해 Sandbox에서 이 기능을 테스트하는 것이 좋습니다. 그런 다음, 사용자가 경험할 수 있는 오류와 비교하여 클릭잭 방어가 추가로 제공하는 혜택을 따져봅니다.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.