Hi,
We are a CPQ ISV and have developed a number of PCF components that are distributed with our managed solution. One PCF component contains an IFRAME with the source URL pointing to our service running in Azure i.e. 3rd party content.
Browsers vendors are evolving to a more restrictive security policy e.g. X-Frame-Options: SAMEORIGIN the prevents clickjacking attacks and and CSFR cookie configuration SameSite=Lax that prevents CSRF.
I have a general question: Are there any plans to deprecate, obsolete or perhaps improve IFRAME support in Canvas or Model-driven apps? Any feedback / guidance is appreciated.