You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Firebase.json配置仅允许自家站点嵌入Google Apps Script的iframe?

解决Google Apps Script嵌入Firebase站点的iframe限制问题

核心思路

Google Apps Script的X-Frame-Options仅支持DEFAULT和ALLOWALL两个选项,要实现仅允许自家Firebase站点嵌入的需求,需在Firebase的firebase.json中配置Content-Security-Policy的frame-ancestors指令,同时保持Apps Script的X-Frame-Options为默认值。

正确的firebase.json配置示例

修改headers中的Content-Security-Policy字段,补充frame-ancestors并指定你的Firebase站点域名(替换为实际域名,如https://your-firebase-project.web.app):

{
  "source": "**",
  "headers": [{
    "key": "Content-Security-Policy",
    "value": "default-src 'self' https://*.googleapis.com https://*.google.com; script-src 'self'; frame-ancestors https://your-firebase-project.web.app;"
  }]
}

关键说明

  • frame-ancestors是控制iframe嵌入权限的核心指令,指定专属域名后,仅该站点能嵌入你的Apps Script项目
  • 不要在Apps Script的doGet()中设置X-Frame-Options为ALLOWALL,保持默认值即可,配合Firebase的CSP配置实现精准限制
  • 配置完成后,需执行firebase deploy --only hosting重新部署Firebase Hosting使配置生效

内容的提问来源于stack exchange,提问作者klewis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 05:24:54