Support embedding Discourse in an iframe

Howdy!

I’m developing a web app, and I’d love to use Discourse as my forums / community discussion platform. One of my main requirements though is that the forum should be able to be opened in an iframe docked to the side of my UI, so that users can browse tutorials, talk to other people, or contact support all within the comfort of the app itself. This is a huge win for UX, and because Discourse is responsive and mobile friendly, a small iframe should work well for this use case. It seems like this would be an awesome feature for Discourse that many people might use.

I saw this old discussion about this topic, which includes one proposed solution.

So I wanted to ask the maintainers and folks here, is this a feature that you would be open to a PR for? Would you consider adding this feature? Are there any issues with that solution that was proposed that would need to be dealt with?

The main issue I see is that of opening up possible Security problems. eg.

Cross Frame Scripting

Interesting, thanks for pointing that out.

If Cross Frame Scripting was a concern, could we allow people to specify a trusted domain(s)?

For example, the ALLOW-FROM URI in the X-FRAME-OPTIONS header. See here.

pasted the wrong URL - link fixed

Yes, sending headers should take care of most if not all security risks.
(I say most because I don’t know if some older browsers might not use the headers)

Okie dokie :thumbsup:

Not being a developer, this thread leaves me puzzled about what the conclusion is regarding embedding discourse in an IFRAME. When you say:

This sounds to me like: problem solved, especially since - in my case - everything would not only be happening under the same domain but even on the same server. But my understaning is also that this is nevertheless not supported and therefore not recommended for people like me. But why? If trusted domains can be specified?

Because it’s an extremely fragile configuration. Discourse expects to control the browser tightly as a JavaScript app. This is not a static 1996 era web page to be slapped in an <iframe> willy-nilly, it’s far more complex.

2개의 좋아요

@codinghorror 이 문제에 대한 업데이트가 있나요? 웹사이트에 캘린더를 임베드할 수 있으면 통일감을 줄 수 있어서 좋겠습니다.

수정: 이 페이지(Julia Programming Language)를 임베드할 수 있으면 좋겠습니다.

no-iframe 지시문을 비활성화하는 숨겨진 설정이 있을 수도 있습니다. 지금은 정확히 기억이 나지 않지만, 그 설정이 있는 데에는 충분한 이유가 있습니다.

이것은 플러그인에 대한 기능 요청에 더 가까운 것 같습니다. 임베드는 전체 페이지와 다르게 표시되어야 합니다.

@j.jaffeux 님에게 참고 요청합니다.

5개의 좋아요

간단한 플러그인이 하나 있습니다. 하지만 작동하지 않습니다. 6년 전에 업데이트된 것이므로, 간단한 수정으로 작동하게 만들 수 있을까요?


   
# name: Allow iFrame embedding
# about: Changes X-Frame-Options so the site can be embedded
# version: 1
# authors: bex-team, riking,

Rails.application.config.action_dispatch.default_headers.merge!({'X-Frame-Options' => 'ALLOWALL'})

제한 없이 Discourse를 iframe에 임베드하려면 두 가지 설정이 필요합니다:

  1. 설정(Settings)에서 CSP 제한을 해제합니다.

  2. 숨겨진 사이트 설정 allow_embedding_site_in_an_iframe을 활성화합니다.

cd /var/discourse
./launcher enter app
rails c
SiteSetting.allow_embedding_site_in_an_iframe=true
exit
exit
2개의 좋아요

@denvergeeks 이 방법을 시도해 봤는데도 제 포럼이 iframe에 임베드되지 않아요.

임베드하려고 하는 사이트의 URL이 무엇인가요?

forum.dreambyte.ai

게시하신 URL은 제 환경에서 전혀 로드가 되지 않습니다… 로드가 가능하게 해 주시면, iFrame 임베딩이 정상적으로 작동하는 제 사이트에서 테스트해 보겠습니다.

Discourse Calendar을 다른 사이트에 임베드할 수 있으면 정말 도움이 될 것 같습니다. 이 부분에 진전이 있나요?