1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Fixed Facebook Canvas

Discussion in 'Resolved Bug Reports' started by The Forum Heroes, Apr 8, 2013.

  1. The Forum Heroes

    The Forum Heroes Well-Known Member

    Using xF inside canvas as a web app, nothing loads other then a white page. I tried with a test version of my fully working 1.1.3 version upgraded to 1.1.4 and also with a fresh 1.1.4 install. Admin back end works fine.
     
    Teapot likes this.
  2. Mike

    Mike XenForo Developer Staff Member

    This is the clickjacking prevention. You will need to edit the ViewRenderer to remove it currently, but I'm looking at making it a config.php option in the future.
     
    The Forum Heroes likes this.
  3. The Forum Heroes

    The Forum Heroes Well-Known Member

    Where is this ViewRenderer located?
     
  4. Mike

    Mike XenForo Developer Staff Member

    library/XenForo/ViewRenderer/Abstract.php

    Remove the X-Frame-Options line (line 54).
     
    0xym0r0n and The Forum Heroes like this.
  5. SchmitzIT

    SchmitzIT Well-Known Member

    We actually filed a ticket on it, but found out it is possible to work around this using <Location> or <Directory> settings in the vhost file for the domain.

    However, it would be great being able to configure the setting in Admin CP.
     
    The Forum Heroes and 0xym0r0n like this.
  6. Mike

    Mike XenForo Developer Staff Member

    It's going to be config.php option because you should know why you want to disable it, as it's a security measure.

    $config['enableClickjackingProtection'] = false;

    Will prevent it from being triggered in 1.1.5.
     
  7. The Forum Heroes

    The Forum Heroes Well-Known Member

    Was this added to 1.1.5?
     
  8. Mike

    Mike XenForo Developer Staff Member

    Yes.
     
    The Forum Heroes likes this.

Share This Page