Strengthen security for embedded apps #3946

Closed
opened 2026-02-21 18:03:57 -05:00 by yindo · 0 comments
Owner

Originally created by @AndyMik90 on GitHub (Jun 2, 2024).

Self Checks

  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing?

When embedding apps on different sites, the URL to the app is exposed on the client side trough the iframe.

2. Describe the feature you'd like to see

Since many like the simplisity of an iFrame embedding, I suggest creating some type of hash or generating the URL on the serverside that can be used in the source for the iFrame url.

3. How will this feature improve your workflow or experience?

Remove the possibility for people to take chatbots/embedded apps and "steal" the URL to embed it on their own site or use a subscription that is not theirs.

4. Additional context or comments

No response

5. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @AndyMik90 on GitHub (Jun 2, 2024). ### Self Checks - [X] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [X] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [X] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? When embedding apps on different sites, the URL to the app is exposed on the client side trough the iframe. ### 2. Describe the feature you'd like to see Since many like the simplisity of an iFrame embedding, I suggest creating some type of hash or generating the URL on the serverside that can be used in the source for the iFrame url. ### 3. How will this feature improve your workflow or experience? Remove the possibility for people to take chatbots/embedded apps and "steal" the URL to embed it on their own site or use a subscription that is not theirs. ### 4. Additional context or comments _No response_ ### 5. Can you help us with this feature? - [ ] I am interested in contributing to this feature.
yindo added the 💪 enhancement label 2026-02-21 18:03:57 -05:00
yindo closed this issue 2026-02-21 18:03:58 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#3946