I'm working on an Outlook Web Add-In and I'm struggling with knowing what value to set for the X-Frame-Options: ALLOW-FROM
header. As far as I know, users may access Outlook via three different domains (office.com, office365.com and live.com). Does anyone know how I can tell which site is making the request, so I can set the header appropriately?
相关问题
- Can't access WordPress Dashboard in an iframe
- Outlook Web App (Exchange 2013 On-Premise) API 1.2
- Outlook Add-in file download
- Office.context.mailbox.item.body.getAsync() method
- Task Pane Addin for outlook Web app
相关文章
- X-Frame-Options ALLOW-FROM a specific site allows
- Outlook WebAddin is detected as contextual addin i
- Pop-up blocked error when opening url from outlook
- Office API call to getUserIdentityTokenAsync() ret
- cors issue with Outlook Add-In
- How to check an Outlook custom property is availab
- No event is fired when closing a dialog via ESC
- Where to store larger data for Outlook Web App?
The add-in needs to be able to run in an iFrame in order to work in Outlook Web, thus X-Frame-Options header should not be included at all. ALLOW-FROM can't really be used because the number of domains to list is way more than 3 mentioned, and that list is growing – there are many cases where various users access Office365 and outlook.com using custom domains.