web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / set X-Frame-Options po...
Power Apps
Answered

set X-Frame-Options powerapps canvas

(0) ShareShare
ReportReport
Posted on by 6

Hi there!

 

I need to set up X-Frame-Options HTTP header to SAMEORIGIN on my Canvas PowerApp.

 

On the settings tab I was not able to find anything related to that.

 

Thank you!

2020-05-11 08_22_29-Microsoft Edge.png
I have the same question (0)
  • ScottDurow Profile Picture
    1,039 on at

    afaik there is no way to make these kind of changes - what is the reason you need to set this option?

  • ygordf Profile Picture
    6 on at

    @ScottDurow, to prevent other sites from framing the application.

  • Verified answer
    ScottDurow Profile Picture
    1,039 on at

    CanvasApps are designed to be able to be embedded - and there is no way of disabling this by adding the X-Frame-Options.
    You could create a PCF component that looked at the top window to see if it's the PowerApps player - and then provide this property to the rest of the App.

     

  • nickmanny Profile Picture
    18 on at

    X-Frame-Options is a header included in the response to the request to state if the domain requested will allow itself to be displayed within a frame. It has nothing to do with javascript or HTML, and cannot be changed by the originator of the request. You can't set X-Frame-Options on the iframe. That is a response header set by the domain from which you are requesting the resource . They have set the header to SAMEORIGIN in this case, which means that they have disallowed loading of the resource in an iframe outside of their domain. So you cannot embed their website into yours. Browsers when see that the response header contains X-Frame-Options: SAMEORIGIN, they check your domain and block the rendering of the <iframe>. It is a security measure to avoid clickjacking.

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Congratulations to the April Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Apps

#1
Vish WR Profile Picture

Vish WR 846

#2
Valantis Profile Picture

Valantis 532

#3
Haque Profile Picture

Haque 410

Last 30 days Overall leaderboard