mirror of
https://github.com/go-gitea/gitea.git
synced 2026-03-22 06:24:14 -05:00
Javascript error: same origin policy #12450
Closed
opened 2025-11-02 10:10:10 -06:00 by GiteaMirror
·
24 comments
No Branch/Tag Specified
main
release/v1.25
release/v1.24
release/v1.23
release/v1.22
release/v1.21
release/v1.20
release/v1.19
release/v1.18
release/v1.17
release/v1.16
release/v1.15
release/v1.14
release/v1.13
release/v1.12
release/v1.11
release/v1.10
release/v1.9
release/v1.8
v1.25.3
v1.25.2
v1.25.1
v1.25.0
v1.24.7
v1.25.0-rc0
v1.26.0-dev
v1.24.6
v1.24.5
v1.24.4
v1.24.3
v1.24.2
v1.24.1
v1.24.0
v1.23.8
v1.24.0-rc0
v1.25.0-dev
v1.23.7
v1.23.6
v1.23.5
v1.23.4
v1.23.3
v1.23.2
v1.23.1
v1.23.0
v1.23.0-rc0
v1.24.0-dev
v1.22.6
v1.22.5
v1.22.4
v1.22.3
v1.22.2
v1.22.1
v1.22.0
v1.23.0-dev
v1.22.0-rc1
v1.21.11
v1.22.0-rc0
v1.21.10
v1.21.9
v1.21.8
v1.21.7
v1.21.6
v1.21.5
v1.21.4
v1.21.3
v1.21.2
v1.20.6
v1.21.1
v1.21.0
v1.21.0-rc2
v1.21.0-rc1
v1.20.5
v1.22.0-dev
v1.21.0-rc0
v1.20.4
v1.20.3
v1.20.2
v1.20.1
v1.20.0
v1.19.4
v1.21.0-dev
v1.20.0-rc2
v1.20.0-rc1
v1.20.0-rc0
v1.19.3
v1.19.2
v1.19.1
v1.19.0
v1.19.0-rc1
v1.20.0-dev
v1.19.0-rc0
v1.18.5
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.4
v1.18.0-rc1
v1.19.0-dev
v1.18.0-rc0
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.17.0-rc2
v1.16.9
v1.17.0-rc1
v1.18.0-dev
v1.16.8
v1.16.7
v1.16.6
v1.16.5
v1.16.4
v1.16.3
v1.16.2
v1.16.1
v1.16.0
v1.15.11
v1.17.0-dev
v1.16.0-rc1
v1.15.10
v1.15.9
v1.15.8
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.14.7
v1.15.0
v1.15.0-rc3
v1.14.6
v1.15.0-rc2
v1.14.5
v1.16.0-dev
v1.15.0-rc1
v1.14.4
v1.14.3
v1.14.2
v1.14.1
v1.14.0
v1.13.7
v1.14.0-rc2
v1.13.6
v1.13.5
v1.14.0-rc1
v1.15.0-dev
v1.13.4
v1.13.3
v1.13.2
v1.13.1
v1.13.0
v1.12.6
v1.13.0-rc2
v1.14.0-dev
v1.13.0-rc1
v1.12.5
v1.12.4
v1.12.3
v1.12.2
v1.12.1
v1.11.8
v1.12.0
v1.11.7
v1.12.0-rc2
v1.11.6
v1.12.0-rc1
v1.13.0-dev
v1.11.5
v1.11.4
v1.11.3
v1.10.6
v1.12.0-dev
v1.11.2
v1.10.5
v1.11.1
v1.10.4
v1.11.0
v1.11.0-rc2
v1.10.3
v1.11.0-rc1
v1.10.2
v1.10.1
v1.10.0
v1.9.6
v1.9.5
v1.10.0-rc2
v1.11.0-dev
v1.10.0-rc1
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-rc2
v1.10.0-dev
v1.9.0-rc1
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.8.0-rc3
v1.7.6
v1.8.0-rc2
v1.7.5
v1.8.0-rc1
v1.9.0-dev
v1.7.4
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.7.0-rc3
v1.6.4
v1.7.0-rc2
v1.6.3
v1.7.0-rc1
v1.7.0-dev
v1.6.2
v1.6.1
v1.6.0
v1.6.0-rc2
v1.5.3
v1.6.0-rc1
v1.6.0-dev
v1.5.2
v1.5.1
v1.5.0
v1.5.0-rc2
v1.5.0-rc1
v1.5.0-dev
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc3
v1.4.0-rc2
v1.3.3
v1.4.0-rc1
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc2
v1.3.0-rc1
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc3
v1.2.0-rc2
v1.1.4
v1.2.0-rc1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.99
Labels
Clear labels
$20
$250
$50
$500
backport/done
💎 Bounty
docs-update-needed
good first issue
hacktoberfest
issue/bounty
issue/confirmed
issue/critical
issue/duplicate
issue/needs-feedback
issue/not-a-bug
issue/regression
issue/stale
issue/workaround
lgtm/need 2
modifies/api
modifies/translation
outdated/backport/v1.18
outdated/theme/markdown
outdated/theme/timetracker
performance/bigrepo
performance/cpu
performance/memory
performance/speed
pr/breaking
proposal/accepted
proposal/rejected
pr/wip
pull-request
reviewed/wontfix
💰 Rewarded
skip-changelog
status/blocked
topic/accessibility
topic/api
topic/authentication
topic/build
topic/code-linting
topic/commit-signing
topic/content-rendering
topic/deployment
topic/distribution
topic/federation
topic/gitea-actions
topic/issues
topic/lfs
topic/mobile
topic/moderation
topic/packages
topic/pr
topic/projects
topic/repo
topic/repo-migration
topic/security
topic/theme
topic/ui
topic/ui-interaction
topic/ux
topic/webhooks
topic/wiki
type/bug
type/deprecation
type/docs
type/enhancement
type/feature
type/miscellaneous
type/proposal
type/question
type/refactoring
type/summary
type/testing
type/upstream
Mirrored from GitHub Pull Request
No Label
type/bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/gitea#12450
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Silther on GitHub (Feb 7, 2024).
Description
I get an error from my browser that Gitea tried to access forbidden elements to to SOP
Gitea Version
1.21.1 (-rootless)
Can you reproduce the bug on the Gitea demo site?
Yes
Log Gist
No response
Screenshots
Git Version
No response
Operating System
No response
How are you running Gitea?
portainer stack
Database
SQLite
@wxiaoguang commented on GitHub (Feb 7, 2024):
It looks like you embedded something strange (not the same origin) into the page.
@Silther commented on GitHub (Feb 7, 2024):
Lol, that should only be a grafical bug of bitwaden.
The same javascript error also happens on the demo website
But will test it with disabled bitwarden.
@wxiaoguang commented on GitHub (Feb 7, 2024):
Could you help to provide the embedded HTML (bitwarden or something else)? Then we can make Gitea ignore these non-same origin resources, then there will be no error anymore.
@Silther commented on GitHub (Feb 7, 2024):
You were correct, it is Bitwarden, still strange that it only happens in firefox (and not in chrome), they are probably more strict.
how can I do that?
@Silther commented on GitHub (Feb 7, 2024):
@wxiaoguang commented on GitHub (Feb 7, 2024):
Could you also try to figure out the outer
iframecode?ps: I proposed a fix #29081.
@Silther commented on GitHub (Feb 7, 2024):
that doesn't seem right
@Silther commented on GitHub (Feb 7, 2024):
was not able to copy it directly
@Silther commented on GitHub (Feb 7, 2024):
when ready I could test it with a rootless docker image
@silverwind commented on GitHub (Feb 7, 2024):
We can't do builds for pull requests, so you'd have to build from source and run that.
What are the minimal steps to reproduce? Just install the Bitwarden extension and open Gitea? Any specific settings made in the extension?
@Silther commented on GitHub (Feb 7, 2024):
it has to firefox, but I think that's all,
@silverwind commented on GitHub (Feb 7, 2024):
Odd, because I'm also a Bitwarden user on Firefox and have never seen this error. There must be something different about your setup.
@Silther commented on GitHub (Feb 7, 2024):
maybe some bitwarden settings?
@silverwind commented on GitHub (Feb 7, 2024):
My extension does not have this "Show auto-fill menu on form fields" option, maybe that is causing the iframe? Try toggling it off. What's the version of your extension? Mine is 2024.1.1.
@Silther commented on GitHub (Feb 7, 2024):
mine too
that's strange as this feature was released a while ago (auto-fill-menu)
@silverwind commented on GitHub (Feb 7, 2024):
As per this the feature is only enabled for Bitwarden Cloud users, which I'm not 😆.
@Silther commented on GitHub (Feb 7, 2024):
I like bitwarden, but decisions like that, I just cannot understand.
Should I create a test Bitwarden account and send the credentials to you?
@silverwind commented on GitHub (Feb 7, 2024):
No, it's fine. https://github.com/go-gitea/gitea/pull/29081 will fix it, one way or another.
@wxiaoguang commented on GitHub (Feb 8, 2024):
1.21 nightly is ready by #29089
@Silther commented on GitHub (Feb 8, 2024):
Will set up a new docker shortly
@Silther commented on GitHub (Feb 8, 2024):
with the nightly docker it works perfectly
how long is the release cycle for the stable (latest) version?
@silverwind commented on GitHub (Feb 8, 2024):
It's not a fixed cycle, but I would expect 1.21.6 in around maybe 1-2 weeks.
@Silther commented on GitHub (Feb 8, 2024):
nice,
thanks for the fast fix
@github-actions[bot] commented on GitHub (Feb 28, 2024):
Automatically locked because of our CONTRIBUTING guidelines