Because the apps are integrated into SAP Build Work Zone, standard edition using iFrames, you need protect your system against clickjacking (or UI redressing) attacks by enabling the clickjacking protection. For this, the Unified Connectivity Framework (UCON Framework) is used to optimize the protection of your RFC and HTTP(S) communication against unauthorized access.
Go to transaction UCONCOCKPIT
and select the HTTP Allowlist Scenario from the list.

Then, in the More menu, select HTTP Whitelist → Setup.

Select both options in the setup menu and save it.

NoteYou can see that the entry
Clickjacking Framing Protection is added in logging mode, which means that the connections are just logged but not checked. In production, it is recommended to set the
Mode to
Active Check and to maintain the patterns of SAP Build Work Zone, standard edition host.
To do that, double-click the row Clickjacking Framing Protection.

Next, the blocked and allowed connections can be viewed and edited. You can add the host of your SAP Build Work Zone, standard edition to the allowlist here.
It should look like this: "<subdomain>.launchpad.cfapps.eu10.hana.ondemand.com"
. The subdomain of the respective SAP BTP subaccount can be found in the BTP cockpit.
