SecurityError: Blocked a frame with origin from accessing a cross-origin frame

Hi,

We have a blocking issue for all plugins.

When a user attempts to use a OneAll plugin we register the following error:

Uncaught SecurityError: Blocked a frame with origin "https://www.mydomain.com" from accessing a frame with origin "https://mydomain.api.oneall.com". Protocols, domains, and ports must match. (where "mydomain" is obviously our domain).

Apparently everything is set correctly and this problem only occurs on a server EC2 without static IP.

Any suggestions?

Thaks in advance.

Best Answer

  • maxgeimaxgeiMember
    Answer ✓
    The problem has been fixed.
    It was caused by wrong redirect from HTTP to HTTPS that did not work on the callback .

Answers

  • Hi,
    Not sure. Here are some suggestions:
    Is there code on the main page trying to access our plugin iframe?
    Maybe the X-Frame-Options is set?

Welcome!

Please sign in to your OneAll account to ask a new question or to contribute to the discussions.

Please click on the link below to connect to the forum with your OneAll account.