<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on iFrame Sandbox Permissions for Custom Visuals in PowerBI ( &amp;quot;allow-scripts&amp;quot; pe in Custom Visuals Development Discussion</title>
    <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Query-on-iFrame-Sandbox-Permissions-for-Custom-Visuals-in/m-p/3970121#M9798</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/753376"&gt;@jeromexshi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All you can do to get successful responses from an endpoint is if the &lt;FONT face="courier new,courier"&gt;Access-Control-Allow-Origin&lt;/FONT&gt; response header is configured as &lt;FONT face="courier new,courier"&gt;*&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;null&lt;/FONT&gt; (as custom visuals have a null origin due to the sandbox impositions). If you cannot work to these constraints, then there is currently no known workaround.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If these have been set, then HTTP(S) endpoints should be callable per usual JS fetch methods.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Daniel&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2024 03:11:14 GMT</pubDate>
    <dc:creator>dm-p</dc:creator>
    <dc:date>2024-06-04T03:11:14Z</dc:date>
    <item>
      <title>Query on iFrame Sandbox Permissions for Custom Visuals in PowerBI ( "allow-scripts" permission)</title>
      <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Query-on-iFrame-Sandbox-Permissions-for-Custom-Visuals-in/m-p/3966595#M9743</link>
      <description>&lt;P&gt;I am writing to seek clarification regarding the iFrame sandbox permissions for custom visuals in PowerBI. Specifically, since the sandbox only supports the "allow-scripts" permission, I am concerned about its impact on cross-domain requests.&lt;/P&gt;&lt;P&gt;Could this limitation be causing issues when attempting to pull origin information or resulting in null values when sending POST/OPTIONS requests to other domains? If so, what solutions are available to address this issue? Additionally, is it possible to loosen the restriction on sandbox permissions, or is there an alternative method to successfully pull origin information under the current constraints?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 10:36:52 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Query-on-iFrame-Sandbox-Permissions-for-Custom-Visuals-in/m-p/3966595#M9743</guid>
      <dc:creator>jeromexshi</dc:creator>
      <dc:date>2024-06-02T10:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Query on iFrame Sandbox Permissions for Custom Visuals in PowerBI ( "allow-scripts" pe</title>
      <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Query-on-iFrame-Sandbox-Permissions-for-Custom-Visuals-in/m-p/3970121#M9798</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/753376"&gt;@jeromexshi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All you can do to get successful responses from an endpoint is if the &lt;FONT face="courier new,courier"&gt;Access-Control-Allow-Origin&lt;/FONT&gt; response header is configured as &lt;FONT face="courier new,courier"&gt;*&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;null&lt;/FONT&gt; (as custom visuals have a null origin due to the sandbox impositions). If you cannot work to these constraints, then there is currently no known workaround.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If these have been set, then HTTP(S) endpoints should be callable per usual JS fetch methods.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Daniel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 03:11:14 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Query-on-iFrame-Sandbox-Permissions-for-Custom-Visuals-in/m-p/3970121#M9798</guid>
      <dc:creator>dm-p</dc:creator>
      <dc:date>2024-06-04T03:11:14Z</dc:date>
    </item>
  </channel>
</rss>

