posted on August 20 • Show version history

On August 20, 2026, Laserfiche Cloud added a setting that lets account administrators control which external websites may embed their public forms and surveys in an iframe. 

What is changing 

  • A new allowlist. In Account Administration > Settings > Content Security Policy, administrators list the origins allowed to embed the account’s public forms and surveys — up to 10, https only, subdomain wildcards supported. 

  • Nothing is blocked before January 7, 2027. Embedded forms load exactly as they do today, configured or not. 

  • Enforcement begins January 7, 2027. Only allowlisted origins may embed your public forms/surveys. Framed anywhere else, the form/survey will not render and the visitor sees a blank frame. 

  • HTTPS-only embedding. From January 7, 2027, a public form/survey will only load if the page embedding it is served over HTTPS. Only https:// origins can be added to the allowlist.

  • Nothing else changes. Forms/surveys that require authentication are not affected. Direct hyperlinks to public forms are also not affected. The allowlist only applies when a public form or survey is embedded in an external website using an iframe.

Action needed: If you embed Laserfiche public forms or surveys on an external website, add those domains before January 7, 2027. If not, no action is needed. 

Instructions for configuring and verifying your allowlist are in the documentation here. 

0 0