Skip to Content
0

Clickjacking protection prevented the Fiori Launchpad to load in a frame

Nov 29, 2016 at 11:30 PM

1.3k

avatar image

Hello All,

We are on SAP NetWeaver Portals 7.40 SP12 and Fiori Launchpad is the entry point. We have a dedicated NetWeaver Gateway system (7.40 SP12) and following central hub deployment architecture for UI5 and Fiori development. When we tried to integrate a standard fiori component (Gateway) into Fiori launchpad (Portal) through Fiori iView template, We are getting the following error.

"Uncaught Error: Clickjacking protection prevented the Fiori Launchpad to load in a frame"

We applied the note "2142551 - Whitelist service for Clickjacking Framing Protection in AS ABAP". We added host name of the Portals in HTTP_WHITELIST table on NetWeaver gateway system. But still getting the same error.

Could you please suggest if there is more to do to resolve the issue.

Thanks,

Sudheer.

10 |10000 characters needed characters left characters exceeded
* Please Login or Register to Answer, Follow or Comment.

8 Answers

John Draper Dec 01, 2016 at 10:25 PM
0

Hi Sudheer,

You really need to set up a web dispatcher in front of your EP and Fiori systems as per this note. There is also a workaround mentioned in that note, but SAP don't recommend it....

Regards,

John

Share
10 |10000 characters needed characters left characters exceeded
Sudheer Chaganti Dec 15, 2016 at 06:28 PM
0

Hello John,

Thanks for your response. We have followed the blog mentioned in the note and set up web dispatcher(F5) as mentioned in the note. Now we could be able see the dynamic number on the tile and launch the iView. But the iViews is disabled. No user interaction is possible on the iView.

Could you please let us know if you have any suggestions.

Thanks,

Sudheer.

Share
10 |10000 characters needed characters left characters exceeded
Phil Ruediger Jan 05, 2017 at 09:47 AM
0

Hello John, hello Sudheer,

same problem here: fiori-disabled-frame.png

Regards,

Phil


Share
10 |10000 characters needed characters left characters exceeded
Troy Cronin
Jan 05, 2017 at 10:14 AM
0

Hi Sudheer

Firstly many thanks for using the SAP Community Forums & a very happy new year to you :)

In relation to the scenario you have described and subsequent issues highlighted you mentioned - NW 7.40 SP12 and Fiori Launchpad is the entry point. You tried to integrate a standard fiori component (Gateway) into Fiori launchpad (Portal) through Fiori iView template, and are getting the following error.

  • "Uncaught Error: Clickjacking protection prevented the Fiori Launchpad to load in a frame"
  • You applied SAP Note "2142551 - Whitelist service for Clickjacking Framing Protection in AS ABAP" and added the host name of the Portals in HTTP_WHITELIST table on NetWeaver gateway system. But still getting the same error.

An important factor here to consider is that all required configurations are setup and maintained accordingly. Any small discrepancy can cause unpredictable and unexpected behaviour in the functional operations. - SAP Note: 2017946 - SAP Fiori application integration with NetWeaver Portal.

Now regarding the issue itself and the problem at hand there have been a few reported issues and also their associated resolutions which are covered in the following note(s): - SAP Note 2031108: SAP Fiori Integration with SAP Enterprise Portal - SAP Note 2008931: Known issue note FLP on EP

I would recommend additionally following 2169722 - Whitelist based Clickjacking Framing Protection in Enterprise Portal

Kindly update me as per your findings.

I greatly appreciate your time and patience and I look forward to receiving your reply.

Kind Regards

Troy Cronin

EP Support Engineer SAP Product Support Global Support Centre Ireland

Active SCN Forum Contributor - Follow Me @ http://scn.sap.com/people/troy.cronin2

Share
10 |10000 characters needed characters left characters exceeded
Sudheer Chaganti Jan 11, 2017 at 04:21 PM
0

Hi Phil,

We had a call with SAP. The reason they have given is, SAPUI5 version on Java (Portal) should be greater than ABAP (Gateway). In our case we are on 1.28 on Java (Portal) and 1.40 on ABAP (Gateway). SAP suggested to upgrade Portal.

Please let me know if you need any other info.

Thanks,

Sudheer.

Show 2 Share
10 |10000 characters needed characters left characters exceeded

Hi Sudheer,

Your SAPUI5 libraries Portal/Java side should match the version on Gateway. See Note 2261419 for more information.

Best regards,

Nick

0

Hi Nick,

Sorry for miscommunication. It should have been said, SAPUI5 version on Java (Portal) should be equal or greater than that of ABAP (Gateway).

Thanks,

Sudheer.

0
Santhosh Kumar Gunda Jan 20, 2017 at 08:27 PM
0

Hi All,

We Whitelist the server and port as per the note "2142551 - Whitelist service for Clickjacking Framing Protection in AS ABAP" in Gatway server ABAP. When we open the Fiori iViews is disabled.

Our SAP ABAP SAPUI5 libraries are on 1.36.1 and we upgraded the portal to NW 7.5 SP 05 which has the SAPUI5 librarie 1.38.6.

Our Portal UI5 Libraires are greater than ABAP.But still have the issue with iViews is disabled.

please suggest if there is more to do to resolve the issue.

thanks

Santhosh

Share
10 |10000 characters needed characters left characters exceeded
Radhika Kuthiala Feb 17, 2017 at 12:12 AM
0

Hi,

Were you able to resolve the issue where the iview displayed content is non editable in FLP?

Regards

Radhika

Show 1 Share
10 |10000 characters needed characters left characters exceeded

Hello Radhika,

We solved the issue by upgrading portals to be on higher version of SAPUI5 than of Netweaver Gateway. It is a prerequisite.

Thanks,

Sudheer.

0
rakesh singh Jun 12, 2017 at 11:07 AM
0

Hi Sudheer,

I am also implementing a similar scenario " FLP integration with SAP Portal" using iview template & using FFP. I would like to know few things from your experience.

1.If web-dispatcher is in place for integration scenario, do we still need to implement sap note "2142551 - Whitelist service for Clickjacking Framing Protection in AS ABAP" to avoid clickjacing issue ?
2.If yes! to above question, is updating "HTTP_WHITELIST" table with portal entry sufficient to avoid clickjacing issue, or do we also need some code modification in SAP GW* for UI component ?

Hoping for your experienced advice on my queries which would make it easier for me to implement required options.

GW* : Gateway

Thanks,

Rakesh

Show 2 Share
10 |10000 characters needed characters left characters exceeded

Hello Rakesh,

After we upgraded portal (UI5 version - to same level or higher than Gateway), We didn't implement note 2142551. Both Remote Catalogs and iView Template approach working for us after upgrade.

I hope this answers your question.

Thanks,

Sudheer.

1

Hi Sudheer,

Thanks for the reply, from your above answer I understand that if portal UI5 version is higher than Gateway, the clickjacking issue won't occur and hence we won't need to apply the Sap Note mentioned above and just web-dispatcher configuration for Portal is sufficient for it to work properly.

Please correct me if I am wrong.

Thanks,

Rakesh

0