Fix Homebox refusing to render inside the Ingress panel - #10
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe Nginx Ingress template hides the upstream ChangesIngress header handling
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The change is limited to the Ingress iframe header behavior and is ready to merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the headers bright Comment |
Proposed Changes
Reported from a real instance: the Ingress panel stays blank, and the browser console says why.
Homebox puts
X-Frame-Options: DENYon every response it sends, from a security headers middleware wired in globally (internal/web/mid/security.go, applied inapp/api/main.go). That is a sensible default for an app that owns its own tab, and it is precisely the header no iframe survives. An Ingress panel is an iframe.The fix stays in the Ingress server block. NGINX hides upstream's header and answers with
SAMEORIGINinstead, which is exactly as far as it needs to go: Ingress serves this app from below the root of the Home Assistant origin, so a same-origin rule lets the panel frame it and nothing else. Direct access is not framed by anything and keeps upstream'sDENYas it is. It is the same shape as theframe-ancestorswidening in the FreshRSS app.How this got through the first time
Every Ingress check on the built image was made with
curl, which does not care whether a response may be framed. The response headers were never on the checklist, and this one only bites once a real browser puts the page inside Home Assistant.Verification
Against the built image, with both server blocks rendered from their templates: straight from Homebox the index answers
X-Frame-Options: DENY; through the Ingress block the index, a deep SPA route and an API call all answerX-Frame-Options: SAMEORIGIN, once, with the headers fromserver_params.confstill present; through the direct port the header is stillDENY.nginx -tis clean.Related Issues
Summary by CodeRabbit