Feature request · Integrations · Blocks work
Allow iframe embedding of protected apps and respect app CSP headers
1 source thread · first seen 2023-05
Summary
Apps protected by authentik can no longer be embedded in a page such as Nextcloud external sites, even with a frame-ancestors header set. The user must open them in a new tab.
- Affects
- Nextcloud users embedding protected services
- Workaround
- Open the protected sites in a new tab
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“Currently it seems not to be possible to embed pages/services protected with Authentik as iframes in other pages”