You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Tomcat配置CSP过滤器后iframe加载报错或页面空白问题求助

Let's figure out what's going on here and get that iframe working properly.

First, let's break down the error message you're seeing:

"Refused to frame 'https://10.10.11.172:8443/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors https://10.10.11.172""

This error isn't about your local Tomcat server's CSP—it's about the target page you're trying to embed (https://10.10.11.172:8443/). That target page has a frame-ancestors policy set to only allow https://10.10.11.172 to embed it. But your local Tomcat page (say, http://localhost:8080 or another address) isn't in that allowed list, so the browser blocks the iframe.

Why your initial fixes didn't work:

  1. Your frame-ancestors filter on Tomcat: This directive controls which external pages can embed your Tomcat pages, not the other way around. It doesn't affect whether your Tomcat page can embed the 10.10.11.172:8443 page.
  2. Switching to frame-src: This was the right direction (since frame-src controls which resources your page can embed as iframes), but you missed two critical details:
    • CSP policies are strict about ports: https://10.10.11.172 and https://10.10.11.172:8443 are considered different origins, so your policy didn't actually allow the target port.
    • Your original doFilter method didn't call chain.doFilter(request, response)—this stops the request from reaching your actual page, which is likely why the page went blank even after the error disappeared.

Step-by-step fixes:

Option 1: Fix the target page's CSP (if you control it)

If you have access to the server hosting https://10.10.11.172:8443/, update its frame-ancestors policy to include your local Tomcat's address. For example:

  • If your Tomcat runs at http://localhost:8080, set:
    frame-ancestors https://10.10.11.172 http://localhost:8080;
    
  • For testing (not recommended for production), you can allow any origin:
    frame-ancestors *;
    

Option 2: Fix your Tomcat's frame-src policy (and verify target page settings)

Update your CSP filter to include the target page's full origin (with port) and ensure you continue the filter chain:

public class CSPFilter implements Filter { 
    public static final String POLICY = "frame-src 'self' https://10.10.11.172:8443;"; 
    @Override 
    public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException { 
        if (response instanceof HttpServletResponse) { 
            ((HttpServletResponse)response).setHeader("Content-Security-Policy", CSPFilter.POLICY); 
        }
        chain.doFilter(request, response); // Critical: Let the request proceed to your page
    } 
    @Override 
    public void init(FilterConfig filterConfig) throws ServletException { } 
    @Override 
    public void destroy() { } 
}

Then, make sure the target page's frame-ancestors policy allows your Tomcat page to embed it (follow Option 1 if you need to adjust that).

Additional checks for blank iframe:

  • Open your browser's DevTools > Network tab, and check if the iframe's request returns a 200 OK status. If it's 403 or another error, that's the core issue.
  • Verify the iframe's src attribute is exactly https://10.10.11.172:8443/ (no typos in domain or port).
  • Check if the target page has an X-Frame-Options header set—if it does, it might override or conflict with the frame-ancestors policy.

内容的提问来源于stack exchange,提问作者VKS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 23:17:43