You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Excel启动时自动加载带查询参数的Office-JS加载项及会话传递咨询

Excel Web Add-ins: Transferring Session Context from Your Main Website

Great question! Let’s break down whether this is supported and the practical workarounds to pass your main site’s session context to an Office JS add-in when users open your Excel documents.

Can Excel Web Add-ins natively support this?

Short answer: There’s no direct, out-of-the-box mechanism to pass session context from your main website directly to the add-in. That’s because add-ins run in isolated contexts (either an iframe or separate process) and are subject to cross-origin restrictions that block direct data sharing with external sites like your main platform. But don’t worry—there are solid workarounds to make this happen.

Practical Workarounds to Transfer Session Context

1. Embed Context in Excel’s Custom Document Properties

One straightforward approach is to inject key session identifiers (like a session ID or non-sensitive user metadata) into the Excel document’s custom properties when you generate it from your main site. Then, your add-in can read these properties using the Office JS API once it loads:

// Inside your Office JS add-in
Office.context.document.properties.load("custom");
Office.context.document.properties.custom.getAsync("mainSiteSessionId", (result) => {
  if (result.status === Office.AsyncResultStatus.Succeeded) {
    const sessionId = result.value;
    // Use this ID to fetch full session context from your main site's backend
  }
});

Pros: Simple to implement, no cross-origin hoops to jump through.
Cons: Only suitable for non-sensitive data (custom properties are visible to users who inspect the document).

2. Use the Office JS Dialog API for Bidirectional Communication

If you need to pass more sensitive or dynamic session data, use the add-in’s Dialog API to open a lightweight page from your main site, then transfer the context via message passing:

  • First, your add-in launches a dialog pointing to a dedicated page on your main site (e.g., /session-transfer.html):
// Inside your add-in
Office.context.ui.displayDialogAsync(
  "https://your-main-site.com/session-transfer.html",
  { height: 0.1, width: 0.1, displayInIframe: true },
  (result) => {
    const dialog = result.value;
    dialog.addEventHandler(Office.EventType.DialogMessageReceived, (args) => {
      const sessionContext = JSON.parse(args.message);
      // Store the context for your add-in to use
      dialog.close();
    });
  }
);
  • Then, the main site’s transfer page reads the current session and sends it to the add-in:
// Inside /session-transfer.html on your main site
const sessionContext = { userId: "user123", authToken: "safe-token-here" };
Office.context.ui.messageParent(JSON.stringify(sessionContext));

Pros: Secure, supports dynamic data, no need to embed data in the Excel file.
Cons: Requires configuring your main site and add-in domains in Office’s trusted list.

3. Backend-Driven Session Validation

For the highest security (especially with sensitive session data), use a backend handshake:

  1. When generating the Excel document from your main site, embed a unique document ID in its custom properties.
  2. When the add-in loads, read this document ID and send a request to your main site’s backend (e.g., GET /api/get-session?docId=abc123).
  3. Your backend verifies that the document ID is linked to an active session, then returns a valid session token or context to the add-in.
  4. The add-in uses this token to interact with your main site’s resources.

Pros: Keeps sensitive session data out of the Excel file, relies on backend validation for security.
Cons: Requires additional backend logic.

Quick Note on Auto-Launching the Add-in

To make sure the add-in loads automatically when users open the Excel file from your main site:

  • Ensure the Excel document is associated with your add-in’s manifest (either by embedding the manifest reference or setting up side-loading in your environment).
  • Users will need Excel configured to allow side-loaded add-ins (this is standard for development/testing; for production, you’ll publish the add-in to the Office Store or your organization’s app catalog).

内容的提问来源于stack exchange,提问作者cskr11

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:22:19