# Support embedding Discourse in an iframe

**URL:** https://meta.discourse.org/t/support-embedding-discourse-in-an-iframe/50405
**Category:** Feature
**Tags:** embedding
**Created:** [20 Setembro , 2016 18:46 UTC](https://meta.discourse.org/t/support-embedding-discourse-in-an-iframe/50405 "2016-09-20T18:46:09Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [21 Fevereiro , 2017 12:20 UTC](https://meta.discourse.org/t/support-embedding-discourse-in-an-iframe/50405/6 "2017-02-21T12:20:15Z")

</div>

Not being a developer, this thread leaves me puzzled about what the conclusion is regarding embedding discourse in an IFRAME. When you say:

> [@Mittineague](#):
>
> aarongray:  
> could we allow people to specify a trusted domain(s)?
> 
> Yes, sending headers should take care of most if not all security risks. (I say most because I don’t know if some older browsers might not use the headers)

This sounds to me like: problem solved, especially since - in my case - everything would not only be happening under the same domain but even on the same server. But my understaning is also that this is nevertheless [not supported](https://meta.discourse.org/t/discourse-not-shown-in-iframe/26970/5) and therefore not recommended for people like me. But why? If trusted domains can be specified?

---

_[View the full topic](https://meta.discourse.org/t/support-embedding-discourse-in-an-iframe/50405)._
