嵌入SharePoint在线文档编辑页时CSP框架报错的解决咨询
报错信息
Refused to frame 'https://xxx-my.sharepoint.com/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com teams.microsoftonline.cn *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com".
已尝试的操作
在Apache2中配置了如下CSP请求头(换行仅为提升可读性,实际无空格):
Header always set Content-Security-Policy "default-src 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com teams.microsoftonline.cn *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com; frame-src 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com teams.microsoftonline.cn *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com; frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com teams.microsoftonline.cn *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com; script-src 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com teams.microsoftonline.cn *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com"
同时尝试配置了X-Frames-Options、x-xss-protection、access-control-allow-origin、access-control-allow-headers,均无效果。
嵌入的iframe代码
sandbox="allow-same-origin allow-scripts allow-popups allow-forms allow-modals" src="https://xxx.sharepoint.com/xxx/xxx/_layouts/15/Doc.aspx?sourcedoc={xxx}&action=edit&AllowTyping=True&wdDownloadButton=True&wdInConfigurator=True"
注:使用action=embedview时可正常嵌入,但需求是以编辑模式打开Excel/Word文档。
解决方案
核心原因:报错来自SharePoint服务器返回的CSP限制,而非你自身网站的CSP配置。你在Apache中设置的
frame-ancestors是控制你的网站被其他站点嵌入的规则,而SharePoint的CSP是限制它自身被哪些站点嵌入,两者完全独立。可行解决路径:
- 使用官方嵌入方案:对于编辑模式的Office文档,采用Microsoft提供的Office JavaScript API或官方嵌入控件,这类方式经过授权,不会触发CSP限制。
- 配置SharePoint允许域名:若你拥有SharePoint站点管理员权限,可将你的网站域名添加到SharePoint的允许嵌入域名列表中(需通过站点设置或全局管理后台配置CSP例外)。
- 替代嵌入方式:若无法修改SharePoint配置,可改为在新标签页打开编辑链接;或通过Office 365 API实现文档编辑功能的集成。
- 检查链接有效性:确认编辑模式的链接是否正确,部分SharePoint站点可能需要额外的权限参数或使用专用的编辑嵌入链接格式。
内容的提问来源于stack exchange,提问作者iKroZz44

