fix: allow the Onramper iframe after client navigation - #113
Conversation
CSP stays with the first document, so a /trade-only frame-src never applied when Trade was opened from another page. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughMiddleware now allows the Onramper iframe origins on every route. The trade-path check was removed. A configuration comment explains that CSP uses the first document response during client navigation. ChangesOnramper CSP handling
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The Onramper iframe remains permitted after navigation to Trade and direct loading of Trade. No actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 ESLint
middleware.tsESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox. next.config.tsESLint skipped: the matched ESLint configuration already failed (missing-dependency). Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the frame-src gate Comment |
CSP stays with the first document, so a /trade-only frame-src never applied when Trade was opened from another page. Co-authored-by: Cursor <cursoragent@cursor.com>
Description
Allows
buy.onramper.comandwidget.onramper.cominframe-srcon every response.CSP stays with the first document, so the
/trade-only exception never applied when Trade was opened from another page. Production does not send that exception at all, so a hard load of/tradeis blocked there too.Verification
frame-srcviolation forhttps://buy.onramper.com/./tradeand confirm the same form.Checked the live headers before this change: staging allows Onramper only on a direct
/traderesponse, and production does not allow it. This branch is not deployed yet.Made with Cursor
Summary by CodeRabbit