How to check if iframe embedding is allowed
-
Open the client’s exam site in a browser.
-
Press F12 to open Developer Tools.
-
Go to the "Network" tab and filter by "Doc."
-
Select the main document and inspect the response headers.
Headers to review:
-
X-Frame-Options:-
DENY– Not embeddable -
SAMEORIGIN– Only same-origin embedding -
Missing – Embedding allowed
-
-
Content-Security-Policy:-
frame-ancestors 'none'– Not embeddable -
frame-ancestors 'self'– Only same-origin -
frame-ancestors https://web.proctor.constructor.app– Embeddable from our app
-
Note:
ALLOW-FROMinX-Frame-Optionsis deprecated and ignored by modern browsers.