Skip to content

Fix2_discourse_comments - #454

Open
Eve00000 wants to merge 1 commit into
mixxxdj:websitefrom
Eve00000:Fix2_discourse_comments
Open

Eve00000 wants to merge 1 commit into
mixxxdj:websitefrom
Eve00000:Fix2_discourse_comments

Conversation

@Eve00000

@Eve00000 Eve00000 commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

add discourse (and youtuve) to framesrc self,
I wonder if discourse changed something in their security and it appeared as the banner caused it

needs to be merged to see the result

for the record: I asked gpt but I received only a non-sense answer

…iscourse changed something which made it appear the banner caused it
@daschuer

Copy link
Copy Markdown
Member

The F12 Firefox >Konsole has this;

🔍 Banner rotation script loaded - waiting for DOM... banner-rotation.js:7:13
🔍 DOM ready, initializing banner... banner-rotation.js:10:17
No banner rotation on this page -> skipping elementsd. banner-rotation.js:50:21
Referrer Policy: Die weniger eingeschränkte Referrer Policy "no-referrer-when-downgrade" für die Website-übergreifende Anfrage wird ignoriert: https://mixxx.discourse.group/javascripts/embed.js embed.js
GET
https://mixxx.discourse.group/embed/comments?embed_url=https://mixxx.org/news/2026-09-21-gsoc-2026-final-report-latenight-qml
NS_ERROR_CSP_FRAME_ANCESTOR_VIOLATION
Content-Security-Policy: Die Einstellungen der Seite haben das Laden einer Ressource (frame-ancestors) auf blockiert, da sie gegen folgende Direktive verstößt: "frame-ancestors 'none'" comments

This a rather old post form 2021:
https://meta.discourse.org/t/csp-frame-ancestors-enabled-by-default/197615

Maybe this change has been applied to our instance recently?

@daschuer

Copy link
Copy Markdown
Member

At least netlify.toml is back to the known working value form 2025:
Eve00000@e004923

@Eve00000

Copy link
Copy Markdown
Contributor Author

Yes, I've see a lot of questions and replies about the 'embedding comments' too ...
adding the url was one of the solutions for the ancestor message.

@daschuer

Copy link
Copy Markdown
Member

Who with discourse admin rights can do this?
@ronso0?

This branch was successfully deployed

1 active deployment
pull/454 c57e7654 Deployed Sep 22, 2026 by Eve00000 via deploy / apply #256
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants