EducationSoftwareStrategy.com
StrategyCommunity

Knowledge Base

Product

Community

Knowledge Base

TopicsBrowse ArticlesDeveloper Zone

Product

Download SoftwareProduct DocumentationSecurity Hub

Education

Tutorial VideosSolution GalleryEducation courses

Community

GuidelinesGrandmastersEvents
x_social-icon_white.svglinkedin_social-icon_white.svg
Strategy logoCommunity

© Strategy Inc. All Rights Reserved.

LegalTerms of UsePrivacy Policy
  1. Home
  2. Topics

KB242380: The View Filter editor is unresponsive when using Clickjacking option "Set X-Frame-Options to DENY" in MicroStrategy Web 9.4.1.


Community Admin

• Strategy


The View Filter editor is unresponsive when using Clickjacking option "Set X-Frame-Options to DENY" in MicroStrategy Web 9.4.1.

SYMPTOM:
In the Strategy Web 9.4.1 Admin page > Security, there is a setting to Prevent clickjacking by adding an X-Frame-Options header to page responses.
 
Note: Refer to tech note KB45652 for more information regarding the clickjacking options.
 
When the "Set X-Frame-Options to DENY" is used, seen below, parts of the Strategy Web 9.4.1 GUI interface are unresponsive.

ka04W000000ObzCQAS_0EM4400000025dK.jpeg

For example, View Filters cannot be used because the settings do not appear when trying to filter on an attribute or metric.
When "Set X-Frame-Options to DENY" is enabled.

ka04W000000ObzCQAS_0EM4400000025dB.jpeg

Expected behavior.

ka04W000000ObzCQAS_0EM4400000025dI.jpeg

STEPS TO REPRODUCE:

  1. In the Strategy Web 9.4.1 Admin page > Security, select Prevent clickjacking by adding an X-Frame-Options header to page responses and Set X-Frame-Options to DENY.
  2. Add a View Filter in a report.

CAUSE:
This is a known issue in Strategy Web 9.4.1.
ACTION:
This issue has been addressed in Strategy Web 10. Upgrade to this version to take advantage of the fix. In Strategy Web 10 the option to set the X-Frame-Options header as DENY will no longer be available to prevent the problem. The solution, both in Strategy 9.4.1 and 10 is to use the "Set X-Frame-Options to SAMEORIGIN" setting. 
 
 


Comment

0 comments

Details

Knowledge Article

Published:

May 31, 2017

Last Updated:

May 31, 2017