Articles in this section

Troubleshooting Signed URL IFrame Embedding: Resolving "Access Denied – The Embed Dashboard Link Is Invalid or Expired" in Bold BI

Published:

Overview

This article explains how to troubleshoot the following error when embedding a Bold BI dashboard using Signed URL Authentication in an iframe:

image.png

This issue can occur even when the dashboard ID, Embed Secret, user information, and expiration timestamp are configured correctly.

Scenario

A user embeds Bold BI dashboards within a custom application using an iframe and wants to eliminate the dependency on:

  • Browser cookies
  • Separate Bold BI login sessions
  • Cookie-based authentication

To achieve this, the user implements Signed URL Authentication for dashboard embedding. However, when accessing the dashboard through the generated embed URL, the following error is displayed:

Access Denied – The Embed Dashboard Link Is Invalid or Expired

Root Cause

The issue occurs when the generated HMAC SHA256 Base64 signature is URL-encoded using the JavaScript encodeURIComponent() method before it is appended to the embed URL.

Incorrect Implementation:

&embed_signature=${encodeURIComponent(signature)} 

The encodeURIComponent() method modifies Base64 characters contained within the generated signature. For example:

+ becomes %2B
/ becomes %2F
= becomes %3D 

As a result, the signature value received by Bold BI differs from the original signature that was generated using the Embed Secret.

Since Bold BI validates the exact signature generated from the embed parameters and Embed Secret, any modification to the signature causes the validation process to fail, resulting in the following error:

Access Denied – The Embed Dashboard Link Is Invalid or Expired

Solution

Do not URL-encode the generated signature.

Append the original HMAC SHA256 Base64 signature directly to the embed URL without modification.

Recommended Implementation

&embed_signature=${signature} 

After applying the change, reload the embedded dashboard. The dashboard should load successfully if all embed parameters and the Embed Secret are valid.

NOTE: After the signature is generated:

  • Do not modify embed secret key.
  • Do not URL-encode the generated signature.

Any change to the signed URL after signature generation will invalidate the signature and cause authentication to fail.

Sample Flow

const embedParameters = parameters.join("&");
 
const signature = await hmacSha256Base64(
cfg.embedSecret,
embedParameters
);
 
return `${dashboardUrl}?${embedParameters}&embed_signature=${signature}`; 

Additional References

Conclusion

When using Signed URL Authentication, the generated HMAC SHA256 Base64 signature must be passed to Bold BI exactly as it was created. Applying encodeURIComponent() to the signature alters its value and causes signature validation to fail, resulting in the "Access Denied – The Embed Dashboard Link Is Invalid or Expired" error. Removing the URL encoding resolves the issue and allows the embedded dashboard to load successfully.

Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
SM
Written by Sammanasu Mary Jesuraj
Updated:
Comments (0)
Access denied
Access denied