<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SIM iFrame SAMEORIGIN issue in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53134#M28284</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I originally posted&amp;nbsp;this as a reply&amp;nbsp;under another topic, but the issue is urgent, and I want others to find this easily in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We fully implemented the Iframe approach using the sandbox gateway, only to discover the production gateway is giving us a sameorigin denial.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is:&lt;/P&gt;&lt;P&gt;- SSL protected site;&lt;/P&gt;&lt;P&gt;- iFrame loading Hosted Payment Form from a form post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When posting to auth.net&amp;nbsp;the form never loads and we get the following in the browser console:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Refused to display '&lt;A href="https://secure2.authorize.net/gateway/transact.dll'" target="_blank"&gt;https://secure2.authorize.net/gateway/transact.dll'&lt;/A&gt; in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN'."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone else seeing this issue? I assume this is something Auth.net needs to fix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would love some weigh-in on this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Charles&lt;/P&gt;</description>
    <pubDate>Sun, 29 Nov 2015 01:52:19 GMT</pubDate>
    <dc:creator>cfahey</dc:creator>
    <dc:date>2015-11-29T01:52:19Z</dc:date>
    <item>
      <title>SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53134#M28284</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I originally posted&amp;nbsp;this as a reply&amp;nbsp;under another topic, but the issue is urgent, and I want others to find this easily in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We fully implemented the Iframe approach using the sandbox gateway, only to discover the production gateway is giving us a sameorigin denial.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is:&lt;/P&gt;&lt;P&gt;- SSL protected site;&lt;/P&gt;&lt;P&gt;- iFrame loading Hosted Payment Form from a form post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When posting to auth.net&amp;nbsp;the form never loads and we get the following in the browser console:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Refused to display '&lt;A href="https://secure2.authorize.net/gateway/transact.dll'" target="_blank"&gt;https://secure2.authorize.net/gateway/transact.dll'&lt;/A&gt; in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN'."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone else seeing this issue? I assume this is something Auth.net needs to fix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would love some weigh-in on this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Charles&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 01:52:19 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53134#M28284</guid>
      <dc:creator>cfahey</dc:creator>
      <dc:date>2015-11-29T01:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53135#M28285</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/19341"&gt;@cfahey﻿&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may help: &lt;A href="http://security.stackexchange.com/questions/67889/why-do-browsers-enforce-the-same-origin-security-policy-on-iframes" target="_blank"&gt;http://security.stackexchange.com/questions/67889/why-do-browsers-enforce-the-same-origin-security-policy-on-iframes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 03:45:48 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53135#M28285</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-11-29T03:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53138#M28287</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/7546"&gt;@RichardH﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However it only confirms that this is an issue on the Auth.net server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you tell me how to get Auth.net to disable the same-origin header (or get my site set in a ALLOW-FROM header), since it improperly prevents placing the payment form inside an iframe?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, this worked successfully in the sandbox, and there is no documentation that says it is not permitted.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 15:47:51 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53138#M28287</guid>
      <dc:creator>cfahey</dc:creator>
      <dc:date>2015-11-29T15:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53139#M28288</link>
      <description>&lt;P&gt;Why don't your switch it to DPM, then you can do whatever you need? DPM and SIM are also the same.&lt;/P&gt;&lt;P&gt;read the DPM section in the SIM doc&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.authorize.net/content/dam/authorize/documents/SIM_guide.pdf" target="_blank"&gt;http://www.authorize.net/content/dam/authorize/documents/SIM_guide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 16:02:07 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53139#M28288</guid>
      <dc:creator>RaynorC1emen7</dc:creator>
      <dc:date>2015-11-29T16:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53140#M28289</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/1353"&gt;@RaynorC1emen7﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While a fine idea, my understanding is that DPM requires the merchant to collect the CC info before posting to the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This means our site would&amp;nbsp;be handling the CC info, which is something we don't want to do, for PCI compliance reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But more importantly, using the SIM in an iFrame works properly&amp;nbsp;in sandbox, and there's no documentation that says it isn't allowed. This seems to be&amp;nbsp;a&amp;nbsp;bug on Auth.net's part that I, and I would think most developers, need fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anyone from Auth.net who can weigh-in with a deifnitve answer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any developers out there successfully using SIM inside an iFrame?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all !&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 19:16:52 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53140#M28289</guid>
      <dc:creator>cfahey</dc:creator>
      <dc:date>2015-11-29T19:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53148#M28297</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/19341"&gt;@cfahey﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We&amp;nbsp;don't&amp;nbsp;recommended using a hosted payment form within an iFrame and are unlikely to&amp;nbsp;make changes if it breaks in production. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;UPDATE: However, if you have Visa Checkout enabled for your production account, it enforces SAMEORIGIN. &amp;nbsp;Disabling Visa Checkout may help resolve this for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 19:43:16 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53148#M28297</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-11-30T19:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53154#M28302</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/7546"&gt;@RichardH﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VISA Checkout was indeed the cause!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for finding us a solution!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the best!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Charles&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 22:27:26 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53154#M28302</guid>
      <dc:creator>cfahey</dc:creator>
      <dc:date>2015-11-30T22:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53160#M28303</link>
      <description>&lt;P&gt;For clarification, does this mean it is NOT possible to use the hosted payment form within an iframe while Visa Checkout is enabled in the account?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently working on a setup that would use the hosted-and-framed payment form for direct payments with the possibility of adding Visa Checkout as a completely separate and non-framed option (not on the hosted payment form) in the near future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to enable Visa Checkout in the account but specifically disable it on the hosted payment form?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fritz&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 16:47:36 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53160#M28303</guid>
      <dc:creator>coppercup</dc:creator>
      <dc:date>2015-12-01T16:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: SIM iFrame SAMEORIGIN issue</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53162#M28305</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/19162"&gt;@coppercup﻿&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A present, the account setting for Visa Checkout&amp;nbsp;determines if it's presented on the hosted payment form and require SAMEORIGEN. &amp;nbsp;It's not currently possible to decouple the two. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are welcome to post this as a new feature using our &lt;A href="http://community.developer.authorize.net/t5/Ideas/idb-p/ideas" target="_blank"&gt;Ideas forum&lt;/A&gt;. This will allow others to vote on and make suggestions to improve the request.&lt;BR /&gt;&lt;BR /&gt;Richard&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 17:21:13 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SIM-iFrame-SAMEORIGIN-issue/m-p/53162#M28305</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-12-01T17:21:13Z</dc:date>
    </item>
  </channel>
</rss>

