Azure静态Web应用与Identity Server的frame-ancestors CSP指令异常问题求助
Azure静态Web应用与Identity Server的frame-ancestors CSP指令异常问题求助
各位好,我最近碰到了一个关于Content Security Policy(CSP)里frame-ancestors指令的棘手问题,折腾好一阵都没搞定,来这儿请教大家!
最开始的情况是这样:我在用Azure静态Web应用,页面嵌入iframe的时候突然报了这个错误:
Refused to frame '<URL>' because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'none'"
我当时以为是Azure静态Web应用这边的CSP配置没到位,就去staticwebapp.config.json里加了全局头配置:
"globalHeaders": { "Content-Security-Policy": "frame-ancestors 'self' https://alpha.sso.###.com https://sso.###.com;" }
而且我特意检查了响应头,确实已经带上了这个CSP配置,但离谱的是,错误还是一直提示策略是'none'。
后来我自己捣鼓了半天,才反应过来问题根本不在Azure静态Web应用这边,而是Identity Server的CSP配置需要调整!
于是我在Identity Server那边设置了frame-ancestors指令:frame-ancestors 'self' https://localhost:5001/,试过带末尾斜杠和不带的两种写法,但现在又遇到了新的错误:
Refused to frame 'https://localhost:5001/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self' https://localhost:5001/".
我就搞不懂了,明明已经把允许的域名加进去了,怎么还是报这个错?有没有朋友遇到过类似的情况?是不是我配置的格式有问题,或者还有什么隐藏的地方需要调整呀?
内容来源于stack exchange
相关产品推荐
相关产品推荐

