X-Frame-Options - https

Moderator: crythias

Post Reply
aeg
Znuny newbie
Posts: 42
Joined: 02 Mar 2017, 15:53
Znuny Version: 5.0.4

X-Frame-Options - https

Post by aeg »

Hi,

I was activating ssl cert on my OTRS web, after that I can't view the content in the tickets.
one of the errors are:
"Error while parsing the 'sandbox' attribute: 'ms-allow-popups' is an invalid sandbox flag.
in a frame because it set 'X-Frame-Options' to 'deny'."

I enabled ths feature "DisableIFrameOriginRestricted" but the content is still not showing up.
Any ideas why?

thanks
jojo
Znuny guru
Posts: 15019
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: X-Frame-Options - https

Post by jojo »

Check your Apache SSL Config and remove the Deny there
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
aeg
Znuny newbie
Posts: 42
Joined: 02 Mar 2017, 15:53
Znuny Version: 5.0.4

Re: X-Frame-Options - https

Post by aeg »

jojo wrote: 20 Sep 2018, 12:07 Check your Apache SSL Config and remove the Deny there
Hi jojo,

"Header always set X-Frame-Options DENY"

is it enough just to remove it, or should I put allow or something ?
jojo
Znuny guru
Posts: 15019
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: X-Frame-Options - https

Post by jojo »

just remove it, OTRS brings own config
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
aeg
Znuny newbie
Posts: 42
Joined: 02 Mar 2017, 15:53
Znuny Version: 5.0.4

Re: X-Frame-Options - https

Post by aeg »

ok thank you jojo.

Can I ask you one more thing,do you know the best method to forward http://exampe and https://example to https://example.company.com fqdn ?
we are using OTRS 6 and apache.
Post Reply