Skip to main content
Idea

Allow Chrome extension embeds

Related products:Lucidchart
  • September 22, 2025
  • 1 reply
  • 37 views

Forum|alt.badge.img

The issue is that Lucid has the following Content Security Policy: frame-ancestors https: http:. This means the Lucid iframe can only render if every ancestor frame up to the top level window has an origin that matches https: or http:.
 
The iframe works when you view the Embed directly on a different platform because it is framed within the context of a traditional URL, for example: 
https://example.com
 
However, Chrome extensions are different from typical websites. At the parent level they use the
chrome-extension:// scheme rather than https:// or http://. Since chrome-extension:// is not permitted by Lucid’s CSP, the connection is being blocked and results in that error message saying that lucid.app refused to connect. Unfortunately, unless LucidChart is willing to update their CSP in order to support iframes in the context of a chrome extension, then embeds viewed within a Chrome Extension App will continue to be blocked when viewed via that method.

September 23, 2025

Hi ​@aaron.mackey, thank you for this feedback. We appreciate the detailed feedback and the time you took to let us know what you’re hoping to see. 

We encourage anyone else who’s interested in this to upvote this post and share any additional details about your use case or what you’d like to see in this experience.

For more information about how we manage feedback in this community, please take a look at this post:

 

Comments

Ambar D
Forum|alt.badge.img+12
  • Lucid community team
  • September 23, 2025

Hi ​@aaron.mackey, thank you for this feedback. We appreciate the detailed feedback and the time you took to let us know what you’re hoping to see. 

We encourage anyone else who’s interested in this to upvote this post and share any additional details about your use case or what you’d like to see in this experience.

For more information about how we manage feedback in this community, please take a look at this post: