Tomcat配置CSP过滤器后iframe加载报错或页面空白问题求助
Let's figure out what's going on here and get that iframe working properly.
First, let's break down the error message you're seeing:
"Refused to frame 'https://10.10.11.172:8443/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors https://10.10.11.172""
This error isn't about your local Tomcat server's CSP—it's about the target page you're trying to embed (https://10.10.11.172:8443/). That target page has a frame-ancestors policy set to only allow https://10.10.11.172 to embed it. But your local Tomcat page (say, http://localhost:8080 or another address) isn't in that allowed list, so the browser blocks the iframe.
Why your initial fixes didn't work:
- Your
frame-ancestorsfilter on Tomcat: This directive controls which external pages can embed your Tomcat pages, not the other way around. It doesn't affect whether your Tomcat page can embed the10.10.11.172:8443page. - Switching to
frame-src: This was the right direction (sinceframe-srccontrols which resources your page can embed as iframes), but you missed two critical details:- CSP policies are strict about ports:
https://10.10.11.172andhttps://10.10.11.172:8443are considered different origins, so your policy didn't actually allow the target port. - Your original
doFiltermethod didn't callchain.doFilter(request, response)—this stops the request from reaching your actual page, which is likely why the page went blank even after the error disappeared.
- CSP policies are strict about ports:
Step-by-step fixes:
Option 1: Fix the target page's CSP (if you control it)
If you have access to the server hosting https://10.10.11.172:8443/, update its frame-ancestors policy to include your local Tomcat's address. For example:
- If your Tomcat runs at
http://localhost:8080, set:frame-ancestors https://10.10.11.172 http://localhost:8080; - For testing (not recommended for production), you can allow any origin:
frame-ancestors *;
Option 2: Fix your Tomcat's frame-src policy (and verify target page settings)
Update your CSP filter to include the target page's full origin (with port) and ensure you continue the filter chain:
public class CSPFilter implements Filter { public static final String POLICY = "frame-src 'self' https://10.10.11.172:8443;"; @Override public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException { if (response instanceof HttpServletResponse) { ((HttpServletResponse)response).setHeader("Content-Security-Policy", CSPFilter.POLICY); } chain.doFilter(request, response); // Critical: Let the request proceed to your page } @Override public void init(FilterConfig filterConfig) throws ServletException { } @Override public void destroy() { } }
Then, make sure the target page's frame-ancestors policy allows your Tomcat page to embed it (follow Option 1 if you need to adjust that).
Additional checks for blank iframe:
- Open your browser's DevTools > Network tab, and check if the iframe's request returns a 200 OK status. If it's 403 or another error, that's the core issue.
- Verify the iframe's
srcattribute is exactlyhttps://10.10.11.172:8443/(no typos in domain or port). - Check if the target page has an
X-Frame-Optionsheader set—if it does, it might override or conflict with theframe-ancestorspolicy.
内容的提问来源于stack exchange,提问作者VKS

