Skip to main content
Participant
December 19, 2024

Embed within iframe (Refused to frame 'https://new.express.adobe.com/' because an ancestor viola…)

  • December 19, 2024
  • 2 replies
  • 386 views

I’m trying to use the embed within an app that’s rendered in an iframe. I added the embedding domain to the allowed domains, but still get this error:

 

> Refused to frame 'https://new.express.adobe.com/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self' [REDACTED].com".

2 replies

freked
Known Participant
September 2, 2025

Hey @Barranca maybe you know something about this scenario? 🙂 I believe the main issue is that the CSP policy only seems to fetch one domain at a time? But I was also checking the setup of your demo site https://demo.expressembed.com and it actually allows for multiple domains at once. Are you doing something special there?

nhung.ng
Participating Frequently
September 2, 2025

Hello, we are having the same issue. Any update on this? Or have you found any solution to deal with this one?