Skip to content

fix: allow the Onramper iframe after client navigation - #113

Merged
0xApotheosis merged 1 commit into
developfrom
fix/onramper-frame-src
Sep 23, 2026
Merged

0xApotheosis merged 1 commit into
developfrom
fix/onramper-frame-src

Conversation

@0xApotheosis

@0xApotheosis 0xApotheosis commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Description

Allows buy.onramper.com and widget.onramper.com in frame-src on every response.

CSP stays with the first document, so the /trade-only exception never applied when Trade was opened from another page. Production does not send that exception at all, so a hard load of /trade is blocked there too.

Verification

  • Open the site root, then go to Trade from the header without a full reload.
  • The Buy Crypto card should show the Onramper form, not a gray frame.
  • The console should not log a frame-src violation for https://buy.onramper.com/.
  • Hard-load /trade and confirm the same form.

Checked the live headers before this change: staging allows Onramper only on a direct /trade response, and production does not allow it. This branch is not deployed yet.

Made with Cursor

Summary by CodeRabbit

  • Bug Fixes
    • Improved the reliability of the Onramper checkout experience when navigating to the trade page within the app.
    • Onramper’s purchase widget now remains available after client-side navigation, including flows that require checkout popups.
  • Documentation
    • Clarified the security configuration supporting the Onramper checkout flow.

CSP stays with the first document, so a /trade-only frame-src never applied when Trade was opened from another page.

Co-authored-by: Cursor <cursoragent@cursor.com>
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c3feb143-f165-4d2f-b0f9-1208cda82371

📥 Commits

Reviewing files that changed from the base of the PR and between 5163043 and b0fd4ff.

📒 Files selected for processing (2)
  • middleware.ts
  • next.config.ts

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Middleware now allows the Onramper iframe origins on every route. The trade-path check was removed. A configuration comment explains that CSP uses the first document response during client navigation.

Changes

Onramper CSP handling

Layer / File(s) Summary
Unconditional Onramper frame sources
middleware.ts, next.config.ts
Middleware removes the trade-path check and adds the Onramper origins to frame-src for every response. The configuration comment documents the client-navigation constraint.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to b0fd4

The Onramper iframe remains permitted after navigation to Trade and direct loading of Trade. No actionable merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: allowing the Onramper iframe after client-side navigation.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

middleware.ts

ESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.

next.config.ts

ESLint skipped: the matched ESLint configuration already failed (missing-dependency).


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the frame-src gate
Onramper paths now all can wait
The trade-path test hops away
CSP holds firm from first display
The checkout iframe finds its way

Comment @coderabbitai help to get the list of available commands.

@0xApotheosis
0xApotheosis merged commit e07f750 into develop Sep 23, 2026
2 checks passed
@0xApotheosis
0xApotheosis deleted the fix/onramper-frame-src branch September 23, 2026 00:50
0xApotheosis added a commit that referenced this pull request Sep 23, 2026
CSP stays with the first document, so a /trade-only frame-src never applied when Trade was opened from another page.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant