Skip to main content
Participant
October 27, 2023

Subject: Issue with Embedding 'https://new.express.adobe.com/' Content

  • October 27, 2023
  • 7 replies
  • 1160 views

Inform you about an issue I am encountering when attempting to embed content from 'https://new.express.adobe.com/' into an iframe on our website.

The specific error message I'm receiving is as follows:

"Refused to frame 'https://new.express.adobe.com/' because an ancestor violates the following Content Security Policy directive: 'frame-ancestors 'self' https://.adobe.io https://.instructure.com https://*.adobe.com https://classroom.google.com https://wakelet.com'."

It appears that our domain is not included in the list of allowed domains specified in the Content Security Policy (CSP) of 'https://new.express.adobe.com/'. We would like to request your assistance in resolving this issue.

We believe that enabling our domain to embed this content will greatly enhance the user experience on our website.

We kindly request your support in one of the following ways:

Update the CSP Policy: If possible, could you please update the CSP policy of 'https://new.express.adobe.com/' to include our domain ([paraclete.ai,staging.paraclete.ai]) in the list of allowed domains for iframe embedding? This would help us resolve the issue.

Alternative Integration: If updating the CSP is not feasible, we would appreciate guidance on alternative methods for integrating content from 'https://new.express.adobe.com/' into our website while respecting your security policies.

7 replies

Participant
May 8, 2024

I nee help too please!, I also have the same issue with localhost:3000

Participant
April 19, 2024
Participant
March 13, 2024

Hello, I'm having a similar issue with v4.

I've fulfilled all the steps in documentation, set *.localhost:4502,localhost:4502 as the allowed domains and copied the code from sample set up available at https://github.com/AdobeDocs/cc-everywhere/blob/main/v4-sample/index.html

 

I'm still getting a CSP error saying: 

Refused to frame 'https://new.express.adobe.com/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self' localhost:4502".

 

Do I need to perform any other actions in regards to api settings?

Community Manager
November 29, 2023

Hi @Shina. -- Just tested your integration from both of your registered domains. You should be good to go!

 

Best, 

 

Amanda

Participant
November 25, 2023

@amanda_h I am getting this error as well, although I just submitted my account for approval. Basically used this as a starter ... https://developer.adobe.com/express/embed-sdk/docs/guides/quick_actions/ and getting that error

Community Manager
October 27, 2023

Hi -- thanks for sharing your error. I recall enabling your integration. Any domains you have registered to your project are subsequently allowed to embed the SDK content. The error you are seeing may be an error on our backend -- you shouldn't be seeing someone else's registered domains. We had some caching issues last week and some developers faced similar issues. Let me investigate this and get back to you. 

 

Best, 

 

Amanda

Ruben Rincon - DevEx
Adobe Employee
Adobe Employee
October 27, 2023

Hi there, it appears you are trying to directly iframe Express. We have a component that allows you to embed functionality of Express into your website https://developer.adobe.com/express/embed-sdk/

Please use that instead.