How-To: Allow website to be included in mobile apps or iFrames

How-To: Allow website to be included in mobile apps or iFrames

Hotelwize websites have strengthen security, by default not allowing the inclusion in iFrames or Mobile Apps. This is achieved by including the Content Security Policy (CSP) for all websites and utilizing the X-Frame-Options http header.

QuoteContent Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft, to site defacement, to malware distribution.

To allow certain websites to by pass CSP, you should use the Advanced Hosting Configuration Plugin. Activate the plugin for the website and then type in the domains you want in the X-Frame-Options Allowed Parent Hosts field.