Bookings IFrame denied

%3CLINGO-SUB%20id%3D%22lingo-sub-810628%22%20slang%3D%22en-US%22%3EBookings%20IFrame%20denied%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-810628%22%20slang%3D%22en-US%22%3E%3CP%3EIve%20just%20setup%20my%20Bookings%20page%20and%20embeded%20it%20on%20my%20Wordpress%20site%20but%20the%20iframe%20is%20being%20denied%20by%20login.microsoft.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CEM%3ERefused%20to%20display%20'%3CA%20href%3D%22https%3A%2F%2Flogin.microsoftonline.com%2Fcommon%2Foauth2%2Fauthorize%3Fclient_id%3DXXXXXXXXXX%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Flogin.microsoftonline.com%2Fcommon%2Foauth2%2Fauthorize%3Fclient_id%3DXXXXXXXXXX%3C%2FA%3E'%20in%20a%20frame%20because%20it%20set%20'X-Frame-Options'%20to%20'deny'.%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20i%20missing%20something%20on%20the%20bookings%20setup%20site%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJK%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-810628%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ebookings%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOutlook%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-810729%22%20slang%3D%22en-US%22%3ERe%3A%20Bookings%20IFrame%20denied%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-810729%22%20slang%3D%22en-US%22%3EI%20don't%20think%20you%20are%20missing%20anything.%20but%20simply%20the%20login%20page%20cannot%20be%20displayed%20in%20a%20frame.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20don't%20know%20much%20on%20this%20topic%2C%20but%20I%20found%20this%3A%3CBR%20%2F%3E%22Due%20to%20the%20popularity%20of%20clickjacking%20on%20the%20internet%2C%20it%20is%20common%20to%20prevent%20login%20pages%20from%20being%20display%20inside%20frames.%20The%20X-FRAME-Options%20meta%20tag%20in%20HTML%20makes%20it%20easy%20for%20providers%20to%20implement%20this%20safeguard%20on%20a%20widespread%20or%20domain%2Forigin-specific%20basis.%22%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fstackoverflow.com%2Fquestions%2F40795633%2Fx-frame-option-deny-error-when-aad-sign-in-in-office-add-in%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fstackoverflow.com%2Fquestions%2F40795633%2Fx-frame-option-deny-error-when-aad-sign-in-in-office-add-in%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-810750%22%20slang%3D%22en-US%22%3ERe%3A%20Bookings%20IFrame%20denied%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-810750%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F14432%22%20target%3D%22_blank%22%3E%40Victor%20Ungureanu%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFound%20the%20answer%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F127485i3129EB7BA561EC06%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20Require%20an%20Office%20365%20account%20from%20my%20org%20to%20book%20enabled%2C%20disabled%20it%20and%20it%20works.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20though%2C%20I%20found%20a%20link%20from%20your%20link%20to%20a%20github%20page%20with%20some%20interesting%20projects.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJK%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-810756%22%20slang%3D%22en-US%22%3ERe%3A%20Bookings%20IFrame%20denied%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-810756%22%20slang%3D%22en-US%22%3EYes%2C%20you're%20right%2C%20that's%20why%20the%20login%20page%20was%20needed%20in%20the%20first%20place.%20Disabling%20the%20option%20to%20%22Require%20an%20Office%20365%20account%20from%20my%20org%20to%20book%22%20is%20not%20going%20to%20redirect%20to%20the%20login%20page%20anymore.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-810758%22%20slang%3D%22en-US%22%3ERe%3A%20Bookings%20IFrame%20denied%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-810758%22%20slang%3D%22en-US%22%3Efound%20this%20too%3A%20-%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fmicrosoft.github.io%2Fbookings-samples%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fmicrosoft.github.io%2Fbookings-samples%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIm%20going%20to%20use%20that%20to%20setup%20the%20azure%20app%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Ive just setup my Bookings page and embeded it on my Wordpress site but the iframe is being denied by login.microsoft.com

 

Refused to display 'https://login.microsoftonline.com/common/oauth2/authorize?client_id=XXXXXXXXXX' in a frame because it set 'X-Frame-Options' to 'deny'.

 

Am i missing something on the bookings setup site?

 

Thanks

 

JK

4 Replies
Highlighted
I don't think you are missing anything. but simply the login page cannot be displayed in a frame.

I don't know much on this topic, but I found this:
"Due to the popularity of clickjacking on the internet, it is common to prevent login pages from being display inside frames. The X-FRAME-Options meta tag in HTML makes it easy for providers to implement this safeguard on a widespread or domain/origin-specific basis."

https://stackoverflow.com/questions/40795633/x-frame-option-deny-error-when-aad-sign-in-in-office-ad...
Highlighted

@Victor Ungureanu 

 

Found the answer:

 

clipboard_image_0.png

 

I had Require an Office 365 account from my org to book enabled, disabled it and it works.

 

Thanks though, I found a link from your link to a github page with some interesting projects.

 

JK

Highlighted
Yes, you're right, that's why the login page was needed in the first place. Disabling the option to "Require an Office 365 account from my org to book" is not going to redirect to the login page anymore.
Highlighted
found this too: -
https://microsoft.github.io/bookings-samples/

Im going to use that to setup the azure app