gpt4 book ai didi

javascript - Google Trends 嵌入和 X-Frame-Options

转载 作者:行者123 更新时间:2023-11-29 20:52:10 27 4
gpt4 key购买 nike

尝试使用 Google Trends 中的嵌入脚本会导致 Chrome 下出现以下错误。

Refused to display 'url' in a frame because it set 'X-Frame-Options' to 'sameorigin'.

我已将脚本放入 index.html 的正文中,并将其托管在本地和外部服务器上。

据我所知,这是为了阻止“点击劫持”,但谷歌提供的脚本不适用于他们自己的浏览器,这似乎很奇怪。 Firefox 工作正常。

这是 Google Trend 嵌入无法与 Google 自己的产品一起使用的根本问题,还是我的服务器设置有问题?

最佳答案

这是因为您的浏览器设置为阻止第三方 cookie。启用第三方 cookie,嵌入式 Google Trends iframe 将起作用。

如果您仔细查看失败的 iframe 请求,它包含以下 header :

p3p: CP="This is not a P3P policy! See g.co/p3phelp for more info."

header 链接到 this page有了这个解释:

In some situations, the cookies we use to secure and authenticate your Google Account and store your preferences may be served from a different domain than the website you're visiting. This may happen, for example, if you visit websites with Google +1 buttons.

Some browsers require third party cookies to use the P3P protocol to state their privacy practices. However, the P3P protocol was not designed with situations like these in mind. As a result, we've inserted a link into our cookies that directs users to a page where they can learn more about the privacy practices associated with these cookies.

关于javascript - Google Trends 嵌入和 X-Frame-Options,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/51358867/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com