Support Articles

Stay Connected

Load Site in an iframe

You may want to allow your site to be embedded in an iframe on a different case (for example, to create a template page with your sites). Allowing a site to be loaded inside of an iframe in another site may allow malicious actors to use your site and brand to trick visitors into clicking the wrong link or submitting data to outside sources. Only enable this option if you want the site to be loaded in an iframe.


Warning


By default, the ability to load your site in an iframe on another site is disabled. We recommend not changing the default unless it is mandatory for your specific site. Sites created before April 5, 2020 are permitted to be displayed in an iframe.


To enable the ability to load the site in an iframe:


  1. In the left panel, click Settings, and then click Site SSL.
  2. Click the Allow site to be loaded in an iframe toggle.


Security Settings

The following security settings have been implemented to inform browsers that the site should not load inside of an iframe:


  • x-frame-options: SAMEORIGIN
  • content-security-policy: frame-ancestors 'self'


The x-frame-options setting is the original version, while content-security-policy is a newer setting that is not fully supported by all browsers, yet. These tell browsers that the site should not be loaded within an iframe.


These settings are implemented by default to implement the best security practices out of the box. Allowing sites not to load within an iframe by default is a small step to prevent sites from being used for ClickJacking. ClickJacking is where a malicious user loads the site inside of some frame, while using the design of the site to try and get users to pass personal information that can be intercepted or collected.



What's

Snappin

Related Articles

By Eddie Cruz 24 Aug, 2021
Expand the capabilities of the website builder with custom HTML. This widget allows you to embed custom code into your site, and can be used to embed third-party widgets such as videos, contact forms, and more. While adding custom code can extend your site's functionality, we recommend you only add code from a trusted source. Only add code if you know exactly what it does and how to troubleshoot it if it does not work. To learn more about using HTML in Developer Mode, see Developer Mode.
By Eddie Cruz 24 Aug, 2021
The editor's interface has three main predefined sections: The top navigation bar, the left panel, and the content area. Each of these predefined sections plays an important role in letting you make your site as awesome as possible.
By Eddie Cruz 24 Aug, 2021
This widget makes it easy for website visitors to send you money using PayPal. You can use the PayPal button both for gathering donations and for selling products.
Share by: