Alvie commented on issue #8382:
URL: https://github.com/apache/superset/issues/8382#issuecomment-1783864563

   > I have added complete blog on integration of embed superset dashboard - 
https://medium.com/@vishalsadriya1224/embedding-apache-superset-dashboards-in-ruby-on-rails-and-react-a-role-level-security-guide-697da01676af
   
   I think disabling CSP, is a somewhat dangerous way of doing it. You should 
copy across the talisman config in config.py to superset_config.py, but allow 
frame ancestors from hosts you choose. Or even '*', but disabling talisman 
altogether and replacing it with custom CORS options is a bit complex and 
potentially dangerous if you do not know what you're doing.
   
   Anyway, yes, from what I can tell, the issue is from the cookie not being 
set, so it is good you are including this.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to