Allow Site to Be Framed Setting in NetSuite 2026.1
The Allow Site to Be Framed feature in NetSuite 2026.1 enables control over framing web pages, impacting session-dependent functionalities.
The Allow Site to Be Framed feature, introduced in NetSuite 2026.1, allows administrators to set HTTP headers that dictate whether web pages can be displayed within an HTML iframe. This flexibility is significant for web store deployment and integration with other applications, but there are important considerations to keep in mind.
Feature Overview
This setting provides three possible configurations:
- Disallow Framing (default setting): Pages can only be framed by the exact same domain/origin. This is the most restrictive option and is recommended for enhanced security.
- Allow Framing: Pages can be framed by any domain/origin. While this eases integration with various services, it may expose the site to security risks.
- Allow Framing Custom: Administrators can specify a list of allowed domains/origins. Only pages from these trusted entities are permitted to frame the web pages, striking a balance between usability and security.
Important Notes
- Session Management: Importantly, while the Allow Framing settings adjust how pages are rendered, they do not change cookie behavior. Session-dependent features like login, cart functionalities, and checkout processes may encounter issues when a web store is framed by a different domain than your SuiteCommerce domain.
- Best Practices: Due to modern restrictions on third-party cookies, using iframes is generally not considered a best practice for web stores. The potential for login and cart failures suggests that careful consideration is necessary before enabling any framing options.
Implementation
To configure the Allow Site to Be Framed setting:
- Navigate to Advanced > Security in the NetSuite UI.
- Adjust the Allow Framing setting as per your requirements.
- Use the SecurityHeaders.json file to incorporate these security headers if customizing at a code level.
Who This Affects
This change primarily impacts:
- Web Developers: Those configuring site integrations will need to understand how framing affects user sessions and security.
- NetSuite Administrators: Responsible for implementing and managing security settings within the platform.
Key Takeaways
- The Allow Site to Be Framed feature empowers control over whether web pages can be nested within iframes.
- It includes options to entirely disallow framing or allow specific domains while keeping security in mind.
- Caution is advised regarding session dependency issues that could arise when framing web pages from different domains.
- The feature reflects a shift towards flexible online commerce solutions while maintaining security protocols.
- Always consider the user experience impacts of allowing your site to be framed by third-party domains.
Frequently Asked Questions (4)
What are the configuration options for the Allow Site to Be Framed setting in NetSuite 2026.1?
How does the Allow Site to Be Framed setting interact with session-dependent features like login or checkout?
Do I need to update any NetSuite configuration files when customizing the Allow Site to Be Framed setting?
Can enabling the Allow Framing option in NetSuite 2026.1 introduce security risks?
Weekly Update History (1)
Updated Allow Site to Be Framed to clarify that the Allow Site to be Framed setting doesn't change how browsers treat cookies or how NetSuite sets session cookies.
View Oracle DocsWas this article helpful?
More in SuiteCommerce Solutions (SC, SCA, SCMA)
- Enable Token-Based Authentication in NetSuite 2026.1
Token-based authentication is now required for developer tools in NetSuite 2026.1, enhancing security and compliance with 2FA policies.
Also from NetSuite 2026.1
- Custom Labels for Additional Item Prices in NetSuite 2026.1
Custom labels enhance transaction summaries in NetSuite, improving clarity for item prices.
- Applied Trans Date and Period Enhancements in NetSuite 20...
Latest updates in NetSuite 2024.1 enhance Accounting SuiteApps with transaction line distribution features.
- Data Not Copied from Production to Sandbox in NetSuite 2026.1
In NetSuite 2026.1, key data like domains and customer roles are not copied to sandbox accounts during refreshes, impacting setup.
- Available Items Only Feature in NetSuite 2026.1
Available items only filtering boosts sales efficiency in NetSuite 2026.1 with Intelligent Item Recommendations.
Advertising
Reach SuiteCommerce Solutions (SC, SCA, SCMA) Professionals
Put your product in front of NetSuite experts who work with SuiteCommerce Solutions (SC, SCA, SCMA) every day.
Sponsor This Category