IntelligenceBank and embedding in third-party sites

Modified on Thu, 24 Sep at 5:13 AM

This article explains why IntelligenceBank does not support being embedded in an iframe on a third-party site, why framing is not yet blocked, and the supported ways to bring IntelligenceBank content into your own site.

Important: Embedding IntelligenceBank in a third-party site is not supported. IntelligenceBank will block third-party framing in a future release, and any existing embedding will stop working at that point.

Our position

IntelligenceBank does not support being embedded in an iframe on a third-party site. There is no supported embedding mode and no documented integration pattern for placing the application inside another website. The behaviour customers may observe today was never designed, built or tested as a feature. IntelligenceBank will block third-party framing in a future release, and customers should not build workflows that depend on it.

What you may see today

If you place IntelligenceBank inside an iframe on another site, it may partially load. This is not a feature. It happens because IntelligenceBank does not yet send a browser policy that blocks framing. Without that policy, browsers allow the frame by default. Enough of the application then renders to give the impression that embedding works. In practice, several parts of the application do not work correctly inside a frame, for the technical reasons described below.

Security reasons

The main security concern is clickjacking. When another site frames IntelligenceBank, it can overlay or disguise the interface. This can trick a signed-in user into actions they did not intend, such as sharing, approving or deleting assets. The risk is higher for IntelligenceBank than for a public website, because your brand assets, compliance records and user permissions sit behind a sign-in. Blocking framing by other sites is the first-line clickjacking control recommended by OWASP. Security reviewers, including our own penetration testers, expect this control to be in place. There is also a practical concern with sign-in. Browsers increasingly restrict cookies inside third-party frames, which makes sign-in and sessions inside another site's iframe unreliable.

Technical reasons

IntelligenceBank is built to run as the main page in the browser window, not as a page inside another site. Many links in IntelligenceBank are designed to open in the full browser window. Inside an iframe, clicking one of these links replaces your site with IntelligenceBank. Several features also coordinate through the top-level browser window. When another site owns that window, those features fail or behave unpredictably. Finally, no feature is built or tested for use inside a third-party frame. Anything that appears to work in a frame today can stop working in any release, without notice.

Why framing is not blocked today

IntelligenceBank is going through a continuous upgrade of its platform. During this upgrade, newer and older parts of the application run side by side. IntelligenceBank connects them using its own internal iframe mechanism. A blanket block on framing would also block this internal mechanism and break the application. For this reason, the framing policy cannot be enforced until the upgrade reaches the stage where the internal mechanism is no longer needed. At that point, IntelligenceBank will block framing by third-party sites. Until then, the absence of a block is a transitional state of the platform. It is not permission to embed IntelligenceBank in another site.

What will change

IntelligenceBank will enforce a browser policy that prevents other sites from framing the application. From that point, any existing embedding of IntelligenceBank in a third-party site will stop working. IntelligenceBank does not provide support for issues that occur inside a third-party frame, either today or after the change. Customers who currently frame IntelligenceBank should plan to move to one of the supported options below.

Supported ways to bring IntelligenceBank content into your site

IntelligenceBank offers several supported ways to bring content into your own website or tools. 

  1. A standard or Single-Sign-On navigation link to seamlessly redirect and authenticate users to IntelligenceBank and its content.
  2. The IntelligenceBank API lets you build custom portals and front ends on top of your IntelligenceBank data.
  3. Connectors and integrations bring assets directly into the tools your teams already use. 
  4. For displaying individual assets on a website, public share links and public asset URLs are the supported route. 

Need help? Contact your Customer Success Manager or submit a request here to choose the right option for your use case.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article