vendredi 27 mars 2015

'X-Frame-Options' is set to 'SAMEORIGIN' while adding custom facebook tab app

I am trying to show this page in a custom facebook tab.


It is giving me the following error:



Refused to display 'http://ift.tt/1Iy6SJP' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN'.


This thread suggests I remove 'XFrameOptionsMiddleware' from MIDDLEWARE_CLASSES.


When I remove that, I get the following error:



CSRF verification failed. Request aborted.


Reason:



Reason given for failure:
Referer checking failed - http://ift.tt/1Iy6SJR does not match http://ift.tt/1Iy6SJP


Don't know what to do.


How to fix this?


Aucun commentaire:

Enregistrer un commentaire