@DV-JF opened this Issue on September 27th 2017

Hi,

I've installed Piwik 3.1.1 in a subfolder like this "https://www.example-one.com/piwik" Everything works fine on this domain, bit when I try to include the iframe for "opt-out" from a different domain eg. "https://www.example-two.com/" I only get an empty iframe.

Refused to display 'https://www.example-one.com/piwik/index.php?module=CoreAdminHome&action=optOut&language=de' in a frame because it set 'X-Frame-Options' to 'sameorigin'.

I've asked my hoster to set X-Frame-Options to allow www.example-two.com but this is not possible :-(

I've also tried to set enable_framed_settings=1 enable_framed_pages=1 in the config.ini.php but with no result.

Is there a workarround for this problem?

Many greets!

@mattab commented on October 2nd 2017 Owner

I've also tried to set enable_framed_settings=1 enable_framed_pages=1 in the config.ini.php but with no result.

Did you add below the [General] section?

and if you create a 'test.html' file and open it with developer console do you see a HTTP header setting x-frame-options in the response?

@DV-JF commented on October 2nd 2017

This is how my config.ini.php looks like:

[General]
salt = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
enable_framed_settings=1
enable_framed_pages=1
trusted_hosts[] = "www.example-two.com"
trusted_hosts[] = "https:// www.example-two.com/"

I'm still getting the error message:
Refused to display 'https://www.example-one.com/analyse/index.php?module=CoreAdminHome&action=optOut&language=de' in a frame because it set 'X-Frame-Options' to 'sameorigin'

and if you create a 'test.html' file and open it with developer console do you see a HTTP header setting x-frame-options in the response?

Where should I create this file on example-one.com/analyse/ ?

@mattab commented on October 3rd 2017 Owner

you could try adding the "example-one.com" in a new trusted_hosts entry as well if Piwik runs off there too?

Where should I create this file on example-one.com/analyse/ ?

yes

Powered by GitHub Issue Mirror