How can I embed my rails app into another website via iframe?
It works nicely with RoR 3, but not with RoR 4:
<iframe src="http://myrailsapp.com/" width="100%" height="50" id="rails_iframe">error!</iframe>
I tried to use verify_authenticity_token
and protect_from_forgery
options in my controller... seems it's something else (but I'm not sure).
upd. Example: http://jsfiddle.net/zP329/
Rails 4
added a defaultX-Frame-Options
HTTP header value ofSAMEORIGIN
. This is good for security, but when you do want youraction
to be called in aniframe
, you can do this:To Allow all Origins:
To Allow a Specific Origin:
Use :after_filter
When you need to use more than one of your
action
in aniframe
, it's a good idea to make a method and call it with:after_filter
:Use it in your controllers like this:
Via: Rails 4: let specific actions be embedded as iframes
This has to do with Rails 4 enabling additional security protocols by default: http://weblog.rubyonrails.org/2013/2/25/Rails-4-0-beta1/
The setting that breaks iFrames on remote sites is X-Frame-Options. By default, this is set to SAMEORIGIN, which prevents the content from being loading cross domain:
You can read about the new default headers here: http://edgeguides.rubyonrails.org/security.html#default-headers
In order to allow the iFrame to work cross domain, you can change the default headers to allow X-Frame across domain.