web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / IFRAME support in Canv...
Power Apps
Unanswered

IFRAME support in Canvas or Model-driven apps

(0) ShareShare
ReportReport
Posted on by 159

Hi,

 

We are a CPQ ISV and have developed a number of PCF components that are distributed with our managed solution. One PCF component contains an IFRAME with the source URL pointing to our service running in Azure i.e. 3rd party content. 

 

Browsers vendors are evolving to a more restrictive security policy e.g. X-Frame-Options: SAMEORIGIN the prevents clickjacking attacks and and CSFR cookie configuration SameSite=Lax that prevents CSRF.

 

I have a general question: Are there any plans to deprecate, obsolete or perhaps improve IFRAME support in Canvas or Model-driven apps? Any feedback / guidance is appreciated.

I have the same question (0)
  • Hemant Gaur Profile Picture
    on at

    Hi @iwaldman , 

    Can you please initiate an email with me on this and share some more details on the issues/potential problems you are seeing with your solution ?  I am not aware of any deprecation plans for iFrames on canvas or model apps.

    I have reached out to engineering too for review and recommendation on this and will update the thread if I have any new information to share. 

     

    Thanks,

    Hemant 

  • iwaldman Profile Picture
    159 on at

    Hi @HemantG, Thanks for the timely response. I will initiate an email shortly. 

  • iwaldman Profile Picture
    159 on at

    Providing a little more context to my question:

     

    WebKit and Chrome are implementing user privacy features to thwart "tracking cookies" and other means of following a user across the Internet without their consent. 

     

    As a part of that effort, those browsers plan to disable third-party cookies entirely by 2022. 

     

    This is not a concern for application UIs that live at the top of the document window, but should be a major concern for any UI that has been typically embedded using an IFRAME in another site (such as a customer's on-premise system, or another cloud service like Dynamics 365 or Salesforce). 

     

    Without cookies (and this includes LocalStorage) embedded SSO will be difficult.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 796 Most Valuable Professional

#2
Michael E. Gernaey Profile Picture

Michael E. Gernaey 327 Super User 2025 Season 2

#3
Power Platform 1919 Profile Picture

Power Platform 1919 268

Last 30 days Overall leaderboard