Re: [lime] Cross-site scripting seemingly preventing firmwar…

Delete this message

Reply to this message
Autor: gothos
Data:  
Para: libremesh
Assunto: Re: [lime] Cross-site scripting seemingly preventing firmware selector from operating
On 12/3/25 17:53, Bob Ham via LibreMesh wrote:
> Hi there,
>
> I'm trying to download an image but the firmware selector won't work for
> me, in a variety of browsers and for any router model. In Firefox,
> there's a big red bar at the top saying:
>
>    "NetworkError when attempting to fetch resource."

>
> Firefox's console shows
>
>     "Cross-Origin Request Blocked: The Same Origin Policy disallows
> reading the remote resource at
> https://firmware-libremesh.antennine.org/.versions.json. (Reason: CORS
> header ‘Access-Control-Allow-Origin’ does not match ‘*, *’)."

>
> I notice that "firmware-libremesh.antennine.org" in that error message
> is not "firmware-selector.libremesh.org", which is the hostname of the
> firmware selector, linked to by https://libremesh.org/ .
>
> Regards,
>
> Bob Ham



Hi, and thanks for reporting!

One nginx reverse proxy was duplicating that header.

Fixed