Skip to content

Fix Homebox refusing to render inside the Ingress panel - #10

Merged
frenck merged 1 commit into
mainfrom
fix-ingress-frame-options
Sep 11, 2026
Merged

frenck merged 1 commit into
mainfrom
fix-ingress-frame-options

Conversation

@frenck

@frenck frenck commented Sep 11, 2026 •

Copy link
Copy Markdown
Member

Proposed Changes

(Describe the changes and rationale behind them)

Reported from a real instance: the Ingress panel stays blank, and the browser console says why.

Refused to display 'http://test.local:8123/' in a frame because it set 'X-Frame-Options' to 'deny'.

Homebox puts X-Frame-Options: DENY on every response it sends, from a security headers middleware wired in globally (internal/web/mid/security.go, applied in app/api/main.go). That is a sensible default for an app that owns its own tab, and it is precisely the header no iframe survives. An Ingress panel is an iframe.

The fix stays in the Ingress server block. NGINX hides upstream's header and answers with SAMEORIGIN instead, which is exactly as far as it needs to go: Ingress serves this app from below the root of the Home Assistant origin, so a same-origin rule lets the panel frame it and nothing else. Direct access is not framed by anything and keeps upstream's DENY as it is. It is the same shape as the frame-ancestors widening in the FreshRSS app.

How this got through the first time

Every Ingress check on the built image was made with curl, which does not care whether a response may be framed. The response headers were never on the checklist, and this one only bites once a real browser puts the page inside Home Assistant.

Verification

Against the built image, with both server blocks rendered from their templates: straight from Homebox the index answers X-Frame-Options: DENY; through the Ingress block the index, a deep SPA route and an API call all answer X-Frame-Options: SAMEORIGIN, once, with the headers from server_params.conf still present; through the direct port the header is still DENY. nginx -t is clean.

Related Issues

(Github link to related issues or pull requests)

Summary by CodeRabbit

  • Bug Fixes
    • Updated iframe security behavior so the app can be embedded within an Ingress while retaining same-origin protection.

@frenck frenck added the bugfix Inconsistencies or issues which will cause a problem for users or implementors. label Sep 11, 2026
@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 65618f08-53a9-44c2-b2b7-4a7b7e1999ba

📥 Commits

Reviewing files that changed from the base of the PR and between 45367dc and 1ee926d.

📒 Files selected for processing (1)
  • homebox/rootfs/etc/nginx/templates/ingress.gtpl

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The Nginx Ingress template hides the upstream X-Frame-Options header and adds SAMEORIGIN with the always flag.

Changes

Ingress header handling

Layer / File(s) Summary
Override X-Frame-Options
homebox/rootfs/etc/nginx/templates/ingress.gtpl
The template hides the upstream X-Frame-Options header and adds X-Frame-Options SAMEORIGIN always.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 1ee92

The change is limited to the Ingress iframe header behavior and is ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: fixing Homebox rendering in the Ingress panel.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-ingress-frame-options

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the headers bright
The frame now fits the site just right
Upstream flags fade away
SAMEORIGIN guards the day
Nginx hops through clean delight

Comment @coderabbitai help to get the list of available commands.

@frenck
frenck merged commit 19e5151 into main Sep 11, 2026
14 checks passed
@frenck
frenck deleted the fix-ingress-frame-options branch September 11, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Inconsistencies or issues which will cause a problem for users or implementors.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant