FAQs

Why is my locally running extension blocked by Chrome's Local Network Access?

Updated:

How to unblock a Tecton extension in development that loads from localhost or a private IP when the Q2 host runs on a deployed HTTPS origin.

Starting with Chrome 142, Chrome requires a user permission — and a matching permissions policy delegation on the iframe — before a publicly hosted page (such as a deployed Q2 host) can embed or make requests to a server on the user's local network or device. If you point a deployed Q2 host at http://localhost:XXXX during development and the iframe fails to load or communicate, Local Network Access (LNA) is the likely cause.

When does this apply?

Setup
LNA prompt?
Action needed
Local Q2 host + localhost iframe
No
None
Local Q2 host + LAN IP iframe
No
None
Dev proxy URL (e.g., https://local-dev-api.q2developer.com/...)
No
None — the browser sees a public HTTPS origin
Deployed HTTPS Q2 host + http://localhost:XXXX iframe
Yes
Add loopback-network to allowDirectives
Deployed HTTPS Q2 host + LAN IP (192.168.x.x, 10.x.x.x, .local) iframe
Yes
Add local-network to allowDirectives

How do I fix it?

Add the appropriate directive to your extension's allowDirectives in your Tecton config. Tecton passes directives through to the iframe's allow attribute, which is what Chrome requires to delegate the LNA permission to the embedded document.

{
  "MyExtension": {
    "allowDirectives": ["loopback-network"],
    "modules": {
      "Main": {
        "url": "http://localhost:3000"
      }
    }
  }
}

The first time the iframe attempts to use the local network, Chrome will prompt the user to allow it. The decision is remembered for the top-level origin, so subsequent loads won't re-prompt.

Use loopback-network for localhost, 127.0.0.1, or [::1]. Use local-network for LAN addresses (RFC1918 ranges like 192.168.x.x, 10.x.x.x, 172.16.x.x–172.31.x.x) and .local hostnames.

Remember to remove it before production

These directives exist to support development workflows where the iframe URL resolves to a local address. Production extension URLs should be public HTTPS origins, in which case no LNA directive is needed or appropriate — remove it from your production config.

Cross-version note

Chrome originally shipped LNA under a single local-network-access directive, which was split into local-network and loopback-network in Chrome 145. The new names are what you want going forward; Chrome still honors the legacy name as an alias.

Associated Pages