Skip to content

XDA-105 Restore Content-Security-Policy header without breaking AzureAD integration - #931

Open
StephenCWills wants to merge 1 commit into
masterfrom
XDA-105
Open

XDA-105 Restore Content-Security-Policy header without breaking AzureAD integration#931
StephenCWills wants to merge 1 commit into
masterfrom
XDA-105

Conversation

@StephenCWills

Copy link
Copy Markdown
Member

MSAL injects a hidden iframe into the login page that it uses to acquire and renew tokens silently in the background. The href attribute of the iframe references the login page itself, so the app must allow the login page to embed itself in an iframe in order for AzureAD authentication to work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant