office365 apps - Office 365 add-in: Content Security Policy issues -
hi office 365 outlook team,
our office 365 add-in specifies following content security policy:
content security policy directive: “frame-ancestors ‘self’ outlook.office365.com outlook.office.com”
this has been working until when office store review team reported error:
refused display ‘our url’ in frame because ancestor violates following content security policy directive: “frame-ancestors ‘self’ outlook.office365.com outlook.office.com”
as if web based outlook not loaded outlook.office365.com or outlook.office.com.
the store team did not provide more details of tests.
can please tell if we're missing other valid office 365/outlook urls in csp?
thank you.
validation takes place on outlook.office.com using standard o365 accounts.
Comments
Post a Comment