OpenShift OAuth Route iframe Blocking Due to X-Frame-Options
Issue
-
Attempts to embed the OpenShift OAuth route in an iframe result in an error due to the
X-Frame-Optionsheader being set toDENY. This issue occurs when the OAuth service is configured with a passthrough route, which restricts modification of HTTP headers. -
Typical error message observed in the browser's developer tools console
Refused to display 'https://oauth-openshift.apps.example.com' in a frame because it set 'X-Frame-Options' to 'DENY'.
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Keycloak via RHSSO for SSO integration
- 26.0.0
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.