# SAMEORIGIN header and embedding public calendar from nextcloud in website

**URL:** <https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468>\
**Category:** ℹ️ Support\
**Tags:** calendar-app\
**Created:** [March 21, 2017, 1:39pm UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468 "2017-03-21T13:39:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vasyugan](https://help.nextcloud.com/user_avatar/help.nextcloud.com/vasyugan/32/3393_2.png) [@vasyugan](https://help.nextcloud.com/u/vasyugan)\
**Post date:** [March 21, 2017, 1:39pm UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/1 "2017-03-21T13:39:10Z")

</div>

It is great that NextCloud 11 finally has the public calendar sharing functionality enabled!

So as soon as I upgraded, I went on to embed [our public calendar](https://owncloud.uferwerk.org/apps/calendar/public/FZS4UEKOEUGJON5N) into [our public event page](https://uferwerk.org/termine/) as an iframe only to find that it is not rendered if the web server send the SAMEORIGIN security header, which I have enabled as nextcloud recommends.  
Our Nextcloud instance has a separate subdomain. Therefore the SAMEORIGIN restriction seems to apply. Is there a way deal with this situation other than to remove the security header? Either to add an exception for the location /apps/calendar/public/ in the nginx server config (if that’s possible) or, which would be the more elegant way, to make our main domain and our nextcloud subdomain play nicely together by making it clear that they can be considered (by the browser?!) as the same domain?

---

<div class="post-metadata">

**Author:** ![tflidd](https://help.nextcloud.com/letter_avatar/tflidd/32/5_5575768a8748004e209b776fc1b2916d.png) [@tflidd](https://help.nextcloud.com/u/tflidd)\
**Post date:** [March 25, 2017, 10:25am UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/2 "2017-03-25T10:25:24Z")

</div>

@LukasReschke  
@MorrisJobke

Would that be a potential use case for user-content (or calender/sharing-content) subdomain?

> <https://github.com/nextcloud/server/issues/2523#issuecomment-265085663>

---

<div class="post-metadata">

**Author:** ![MorrisJobke](https://help.nextcloud.com/user_avatar/help.nextcloud.com/morrisjobke/32/19_2.png) [@MorrisJobke](https://help.nextcloud.com/u/MorrisJobke)\
**Post date:** [March 26, 2017, 4:31am UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/3 "2017-03-26T04:31:21Z")

</div>

> [@tflidd](#):
>
> Would that be a potential use case for user-content (or calender/sharing-content) subdomain?

@LukasReschke Why does the public link page does not work? There should be usually nothing hidden or private, because all the authentication information is in the URL and cookies should not be a problem, right?

---

<div class="post-metadata">

**Author:** ![georgehrke](https://help.nextcloud.com/user_avatar/help.nextcloud.com/georgehrke/32/912_2.png) [@georgehrke](https://help.nextcloud.com/u/georgehrke)\
**Post date:** [March 26, 2017, 8:56am UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/4 "2017-03-26T08:56:35Z")

</div>

@LukasReschke has been looking into this yesterday and will send a pull request to the calendar 🙂

---

<div class="post-metadata">

**Author:** ![Borisbudini](https://help.nextcloud.com/letter_avatar/borisbudini/32/5_5575768a8748004e209b776fc1b2916d.png) [@Borisbudini](https://help.nextcloud.com/u/Borisbudini)\
**Post date:** [April 2, 2017, 9:12am UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/5 "2017-04-02T09:12:29Z")

</div>

Any update into this?

---

<div class="post-metadata">

**Author:** ![rodrigoborges](https://help.nextcloud.com/user_avatar/help.nextcloud.com/rodrigoborges/32/7763_2.png) [@rodrigoborges](https://help.nextcloud.com/u/rodrigoborges)\
**Post date:** [February 25, 2019, 2:37pm UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/6 "2019-02-25T14:37:17Z")

</div>

I am trying to embed a public calendar link to another domain, using NC. 14.0.6 .  
I still get  
`Refused to display 'https://XXX/index.php/apps/calendar/embed/3RQALNLiTfF7GHTe' in a frame because it set multiple 'X-Frame-Options' headers with conflicting values ('ALLOW, SAMEORIGIN'). Falling back to 'deny'`

Isn’t there any way to embed the calendar on a different domain currently?

---

<div class="post-metadata">

**Author:** ![vasyugan](https://help.nextcloud.com/user_avatar/help.nextcloud.com/vasyugan/32/3393_2.png) [@vasyugan](https://help.nextcloud.com/u/vasyugan)\
**Post date:** [October 4, 2019, 12:30pm UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/7 "2019-10-04T12:30:40Z")

</div>

It seems the actual culprit is Content-Security-Policy, because Nextcloud seems to set its own strict values for that header. I tried to manually set a value for that header in the NGINX config, but it seems that nextcloud generates code that overrides whatever I set. It seems, that therefore embedding a public calendar is therefore all but impossible.

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [November 27, 2024, 8:29pm UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/8 "2024-11-27T20:29:50Z")

</div>



---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 9, 2024, 1:19pm UTC](https://help.nextcloud.com/t/sameorigin-header-and-embedding-public-calendar-from-nextcloud-in-website/10468/9 "2024-12-09T13:19:40Z")

</div>


