Notifications

500 views

Description

The modal popup window to authenticate an approval fails when SSO is configured for an instance. When the browser is enabled for Developer Tools to evaluate the Javascript console, there is an error message specifying that the x-frame-options has not been configured for the target site.

The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object>. In order to secure a website from Cross Site Scripting attacks the X-Frame-Options header is applied the value DENY or SAMEORIGIN.

A demonstration of the affect of this can be seen in this video:

https://www.youtube.com/watch?v=CqzX03X0gsQ&feature=youtu.be

 

Steps to Reproduce

 

  1. Configure instance to utilize the e-Signature application
  2. Configure instance utilize the Multi-Provider SSO Plugin
  3. Login to the instance via SSO
  4. Navigate through an approval process

Workaround

In order to correct this issue the X-Frame-Options header for the site providing your instance, its IDP service must be configured. Since this is a third party action, unfortunately, Service Now can not assist in this. However, there are many useful resources available on the internet where cross site scripting attack prevention is discussed at length. For example:

https://www.webmasterworld.com/webmaster/4022867.htm


Related Problem: PRB1095939

Seen In

There is no data to report.

Associated Community Threads

There is no data to report.

Article Information

Last Updated:2018-07-23 13:07:31
Published:2017-09-22