You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iframe嵌入场景下AWS Amplify Google SSO登录被X-Frame-Options拦截的解决方案咨询

iframe嵌入场景下AWS Amplify Google SSO登录被X-Frame-Options拦截的解决方案咨询

我用Next.js开发了一个小部件(widget),需要嵌入到第三方网站的iframe中使用。这个小部件支持两种登录方式:邮箱/密码登录和Google单点登录(SSO),后端采用AWS Cognito做认证服务,前端依赖版本为"aws-amplify": "^6.0.13"的库来实现认证逻辑。

目前邮箱/密码登录功能一切正常,但当尝试在iframe中使用Google SSO登录时,登录流程直接被拦截,浏览器抛出了如下错误:

Refused to display 'https://your-cognito-domain.auth.us-east-1.amazoncognito.com/login?response_type=code&client_id=your_client_id&redirect_uri=https://your-redirect-uri' in a frame because it set 'X-Frame-Options' to 'deny'.

我明白这是因为Cognito的登录页面设置了X-Frame-Options: DENY的安全头,出于安全考虑禁止在iframe中加载,但我现在需要找到一个可行的方案,让Google SSO能在iframe的场景下正常工作。

我的配置片段如下:

import { ResourcesConfig } from "aws-amplify"...

备注:内容来源于stack exchange,提问作者Vladan Mikic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 08:48:10