So in-order to solve this I have below options to deal with clickjacking:
Remove the X-frame-options header from slingmainservlet
Install third party plugins on client machines similar to this or this -- this is not recommend for obvious reasons as this is a third party and we are installing on clients machine which will have access to user data
Install legacy browser and use directive ALLOW-FROM -- If you apply it and the browser does not support it, then you will have NO clickjacking defense in place. So a big NOPE
I couldn’t think of any other options unfortunately. Adobe amazes me everyday, they tell us about all these awesome security recommendations and they themselves never follow it, why even give a connector which works only as an iframe..