Trying to start an Apple Pay session from a document with an different security origin than its top-level frame

Viewed 1421

Problem:

I have ApplePay on my website (https://www.example.com/order), it works and successefull pay.

Now I try to integrate IFrame (src="https://www.example.com/order") in subdomain (https://sub.example.com) with form, which contains apple pay and get an error

Trying to start an Apple Pay session from a document with an different security origin than its top-level frame

Both sites used Https.

Main domain (with and without www) and subdomain verified in apple developer account.

2 Answers

This error can be found in the webkit source

if (!ancestorDocument->securityOrigin().isSameSchemeHostPort(topOrigin))
    return Exception { InvalidAccessError, "Trying to start an Apple Pay session from a document with an different security origin than its top-level frame." };
}

isSameSchemeHostPort function checks that the protocol, domain and port of the iframe and page are the same

return a.protocol == b.protocol
    && a.host == b.host
    && a.port == b.port

As a result, the protocol, domain, and port of the frame and page must be the same to integrate iframe with ApplePay.

You can't use Frames with Apple Pay as it is considered bad practice

Related