Publish shop snippets and trusted origins

Availability
Beta

Use Snippets and security to maintain HTML, JavaScript, CSS and the external services that your shop trusts as one revision.

Before you start

Have an approved snippet and a list of HTTPS origins supplied by its provider. Review privacy, consent and availability before trusting a service. KORONA Event manages the permissions required by its shop and payment integrations separately; you cannot change the live security mode here.

Save a complete draft

  1. In the backoffice, open Shops, select your shop and open Code snippets.
  2. Add or edit the HTML/JavaScript and CSS snippets. Keep the intended order and choose the HTML snippet position.
  3. Enter the provider's origins in the appropriate Trusted origins fields, separated by commas.
  4. Select Save draft. This saves HTML, CSS and all origin categories together. It does not publish them.
Shop snippet editor with draft actions and separate trusted-origin categories
Save a complete draft before previewing or publishing it.

Use an exact origin such as https://cdn.example.com or https://cdn.example.com:8443. Do not include a path, trailing slash, wildcard, username, password, query or fragment. Each category supports up to 32 origins.

FieldWhat you trust
ScriptsExternal JavaScript loaded by snippets.
Connections (fetch, analytics)Network requests from scripts.
Frames loaded by the shopWebsites displayed inside your shop.
ImagesImage resources.
StylesheetsExternal CSS resources.
FontsFont resources.
Websites allowed to embed the shopParent websites that display your shop in an iframe.

The last category is separate from Frames loaded by the shop. Adding a website as a loaded frame does not allow that website to embed your shop. Inline CSS remains supported for compatibility; inline event handlers and dynamic JavaScript evaluation do not gain permission automatically.

Preview the saved revision

  1. Save any local edits. Preview and publish are unavailable while changes are unsaved.
  2. Select the Shop domain and Preview mode.
  3. Choose Discovery (report only) to observe policy violations without blocking resources, or Enforcement rehearsal to block resources outside the candidate policy.
  4. Select Open isolated preview.

The preview executes only the saved snippets. It is isolated from shop sessions and contains no cart, checkout or payment context. It does not verify complete provider flows or whether a parent website can embed the shop. Browser reporting also depends on report collection being available. A quiet preview is not proof that a complete purchase will work. Plan a separate full buying-path check before making a customization available to customers.

If the preview is unavailable or expires, return to settings and create another preview. A later saved draft does not change a preview already open.

Publish and follow the status

Select Publish complete draft, review the confirmation and confirm. Publication applies the complete saved revision, including all origin grants.

Publication statusMeaning and next action
UnpublishedThis workflow has not published a revision yet. Existing shop snippets remain in use.
PropagatingDistribution is in progress. Select Refresh status to check again.
ActiveDistribution of the published revision has been verified.
Publication failedDistribution could not be verified. Refresh the status, restore an earlier published revision if appropriate, or contact support if the failure remains. Do not assume the revision is active.

Already open tabs retain their previous policy until a full page reload or navigation that loads a new document. Saving a draft never means it is active.

Restore an earlier revision

Under Revision history, select Restore this published revision for the revision you need. Confirm only after checking its identifier and timestamp. Restoration replaces the complete saved draft and publishes that earlier HTML, CSS and origin set together. It must propagate again. Draft-only entries cannot be restored this way.

If another editor changed the saved draft, the operation fails and preserves your local edits. Copy anything you want to retain, then select Reload saved draft and confirm discarding local edits. Reapply your changes to the latest draft before saving.

Review browser reports

Browser reports shows the last synchronization time, whether data may be stale and whether only a limited selection is available. No synchronization and an empty synchronized result are different states. An empty result does not establish that all resources work.

Counts are browser claims, not proof of an attack or a failed purchase. Preview reports are identified separately. Review the reported service and the relevant category before selecting Add origin to draft. This action is available only for valid HTTPS origins with an identifiable category. It changes the local draft and never publishes automatically.

Ready to Get Started?

Book a free demo or reach out — we’d love to hear from you.