Hello,
I have a Canvas app with an Iframe PCF component that I am looking to use to display the version history for selected SharePoint list items.
In the PowerApps studio, this works as expected with no issues, but once the app is published the Iframe shows domain.sharepoint.com refused to connect and the error given from the dev console is:
'Refused to frame 'https://domain.sharepoint.com/' because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com teams.cloud.microsoft *.office365.com goals.cloud.microsoft *.powerapps.com *.powerbi.com *.yammer.com engage.cloud.microsoft word.cloud.microsoft excel.cloud.microsoft powerpoint.cloud.microsoft *.officeapps.live.com *.office.com *.microsoft365.com m365.cloud.microsoft *.cloud.microsoft *.stream.azure-test.net *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com".'
As *.powerapps.com is mentioned here and the app is connecting from apps.powerapps.com I do not understand why this doesn't work, is there any way to see the full path this takes or where this is falling down? This is O365 SharePoint so the fixes I've seen online for changing CSP headers in IIS are not possible here unfortunately. See screenshots for what shows in the studio vs published app.
Any help or guidance on this would be appreciated.