Unable to embed iframe with source external to site #2728

Closed
opened 2026-02-05 04:56:19 +03:00 by OVERLORD · 2 comments
Owner

Originally created by @kaylahynes on GitHub (Mar 29, 2022).

Describe the Bug

Embedded Iframes from external sources are shown as blocked due to some sort of environment variable.

Steps to Reproduce

Create new page

Embed iframe from an external source(eg. google forms)

Expected Behaviour

Successful embed

Screenshots or Additional Context

image

Browser Details

Google Chrome

Exact BookStack Version

Latest

PHP Version

No response

Hosting Environment

Ubuntu 20.04 LTS Server

Originally created by @kaylahynes on GitHub (Mar 29, 2022). ### Describe the Bug Embedded Iframes from external sources are shown as blocked due to some sort of environment variable. ### Steps to Reproduce Create new page Embed iframe from an external source(eg. google forms) ### Expected Behaviour Successful embed ### Screenshots or Additional Context ![image](https://user-images.githubusercontent.com/5714193/160499096-9632128f-be36-45e0-a33c-09c3a1019650.png) ### Browser Details Google Chrome ### Exact BookStack Version Latest ### PHP Version _No response_ ### Hosting Environment Ubuntu 20.04 LTS Server
OVERLORD added the 🐛 Bug label 2026-02-05 04:56:19 +03:00
Author
Owner

@ssddanbrown commented on GitHub (Mar 29, 2022):

Hi @meepmeep22,
This is not a bug but a security measure to control content within your BookStack instance via browser CSP controls.
Please see the "IFrame Source Control" section of our security documentation for more detail:
https://www.bookstackapp.com/docs/admin/security/#iframe-src-control

@ssddanbrown commented on GitHub (Mar 29, 2022): Hi @meepmeep22, This is not a bug but a security measure to control content within your BookStack instance via browser CSP controls. Please see the "IFrame Source Control" section of our security documentation for more detail: https://www.bookstackapp.com/docs/admin/security/#iframe-src-control
Author
Owner

@ssddanbrown commented on GitHub (Apr 3, 2022):

Since there's been no further follow-up or discussion I'll close this off.

@ssddanbrown commented on GitHub (Apr 3, 2022): Since there's been no further follow-up or discussion I'll close this off.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/BookStack#2728