Skip to content

Expose an interface to $allowedFrameAncestors in configuration #25777

Open
@alfiepates

Description

@alfiepates

How to use GitHub

  • Please use the 👍 reaction to show that you are interested into the same feature.
  • Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
  • Subscribe to receive notifications on status change and new comments.

Is your feature request related to a problem? Please describe.
Can't embed file sharing links as iFrames in other websites due to Content Security Policy.

Describe the solution you'd like
Ideally Nextcloud should expose an interface to $allowedFrameAncestors (ContentSecurityPolicy.php) in configuration.

Describe alternatives you've considered
Right now, I'm manually patching the above file to include the domains I want to embed iFrames on.

Additional context
We're using Nextcloud as an easy way to host PDFs/etc as part of a larger platform, since it's approachable to non-technical content writers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions