Friction

Feature request · Integrations · Blocks work

Allow iframe embedding of protected apps and respect app CSP headers

1 source thread · first seen 2023-05

Summary

Apps protected by authentik can no longer be embedded in a page such as Nextcloud external sites, even with a frame-ancestors header set. The user must open them in a new tab.

Affects
Nextcloud users embedding protected services
Workaround
Open the protected sites in a new tab

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Currently it seems not to be possible to embed pages/services protected with Authentik as iframes in other pages”

Report this item