# 登录用户无法加载 Favicon

**URL:** https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952
**Category:** Support
**Created:** [2018 年12 月 23 日 16:06 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952 "2018-12-23T16:06:06Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2019 年1 月 1 日 22:18 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/22 "2019-01-01T22:18:56Z")

</div>

> [@sam](#):
>
> All of this magic can be nuked now thanks to @tgxworld’s changes as a favicon is guaranteed to be on-site now due to it being a proper upload.

We still need the proxy for until the old `SiteSetting.favicon_url` is removed. We’re currently deprecating it in the next release.

```plaintext
$ wget https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png
--2019-01-02 06:15:32-- https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png
Resolving dungeon.gg (dungeon.gg)... 35.199.105.252
Connecting to dungeon.gg (dungeon.gg)|35.199.105.252|:443... connected.
ERROR: cannot verify dungeon.gg's certificate, issued by ‘CN=COMODO RSA Domain Validation Secure Server CA,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB’:
  Unable to locally verify the issuer's authority.

```

Not sure if it is just me but I can’t seem `curl` or `wget` the upload. It works fine for me in the browser though.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [2019 年1 月 1 日 23:38 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/23 "2019-01-01T23:38:54Z")

</div>

> [@tgxworld](#):
>
> We still need the proxy for until the old `SiteSetting.favicon_url` is removed.

If we only need it for a particular combination of a) weird browsers and b) weird configurations where the favicon URL is totally off-site then I say we pull it ASAP.

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 1 日 23:48 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/24 "2019-01-01T23:48:59Z")

</div>

Hey Alan!

Why does this happen? I’ve noticed that some browsers also accuse my website of not being secure because they cannot verify the certificate’s issuer. It’s a paid certificate and as you can see, it’s issued by COMODO, which is very well known.

---

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2019 年1 月 2 日 00:20 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/25 "2019-01-02T00:20:29Z")

</div>

@sam will have more context since he added the proxy but I don’t think we can remove it since we want to allow favicons to be served via the CDN.

> <https://github.com/discourse/discourse/blob/0daaae1cf37c269de5306daca3996e02174534e4/app/controllers/static_controller.rb#L106-L111>

For this particular problem, it is something odd about @neemiasvf’s SSL setup:

```plaintext
$ openssl s_client -connect dungeon.gg:443 
<truncated>
Verify return code: 21 (unable to verify the first certificate)

```

@neemiasvf How do you have your SSL configured? Are you on the docker based install?

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 00:25 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/26 "2019-01-02T00:25:08Z")

</div>

I followed this tutorial: [Allow SSL / HTTPS for your Discourse Docker setup](https://meta.discourse.org/t/advanced-setup-only-allowing-ssl-https-for-your-discourse-docker-setup/13847)

Could you try this command again? It returned the following for me:

> **Summary**
>
> ```plaintext
> $ openssl s_client -connect dungeon.gg:443
> CONNECTED(00000005)
> depth=0 OU = Domain Control Validated, OU = PositiveSSL, CN = dungeon.gg
> verify error:num=20:unable to get local issuer certificate
> verify return:1
> depth=0 OU = Domain Control Validated, OU = PositiveSSL, CN = dungeon.gg
> verify error:num=21:unable to verify the first certificate
> verify return:1
> ---
> Certificate chain
> 0 s:/OU=Domain Control Validated/OU=PositiveSSL/CN=dungeon.gg
> i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
> ---
> Server certificate
> -----BEGIN CERTIFICATE-----
> MIIHSzCCBjOgAwIBAgIQOsbI6HKtCalptsvvPrwnbjANBgkqhkiG9w0BAQsFADCB
> kDELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
> A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxNjA0BgNV
> BAMTLUNPTU9ETyBSU0EgRG9tYWluIFZhbGlkYXRpb24gU2VjdXJlIFNlcnZlciBD
> QTAeFw0xODExMDIwMDAwMDBaFw0xOTA4MTEyMzU5NTlaME4xITAfBgNVBAsTGERv
> bWFpbiBDb250cm9sIFZhbGlkYXRlZDEUMBIGA1UECxMLUG9zaXRpdmVTU0wxEzAR
> BgNVBAMTCmR1bmdlb24uZ2cwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoIC
> AQC7I4YQQco3PGOjnBxpkKywvYuNVm7nbJ+7cgp+JH702Sm+N8tzEcYGKh/JOle6
> NRkQIW1I9Tb1Yx4dGMYRwUyi8F3D1D2bYQzytzF46IkwApcB8fRW1/mZh2Ys5tnF
> jwLPwK2RJNGzgR/rE0iqLPH4SvG5WhSsYqOCXGf5u9W0PIcoRZJWNwp7sotHjF2D
> JMT5bJJJRQLEGADh+6N6hIsKiIcHeQB6VqQPjy4f5+kyj5zVI+epaDqkmDdmzF80
> QSFT7rLfgNfS4AayUi53ME5Z/NKLdHwLjbNFAUGSjicQ69ExEEXpFb+O8/9yXajK
> BwQpArghFGFZlAR/rMu9LBDaxlZ4Wh+B3EP4iXt4kxCYu/m9e82rEFV1oKc1OhLr
> uISf2Zq9TpkEVXLhfeetX9irHWxb9KYxkuQKsNzXolI3SHKBx3q0vcPBltYTUyEa
> yLAXmrT3PiPJizbPTZivr0TUXk+zLflaC+nyjEJyNMgKDDF1cCxjy95yYcGvfLJk
> HW8/GvpJ/M9Rz+BCR2G0PJm6ARsYTakUPNdBABMJXLO1VRmJ8USh3HFfQqlMRen0
> 1XmwmyYgEPy5CogP1VQ3/JQ2j/Acz4CdYZX61nmqoLn3QhByDfFU89C98N566Jwh
> 3Ed5fymWKsxpxiLYEtYnPH++rHT4epdN1kpBVzHvjYxgUwIDAQABo4IC4DCCAtww
> HwYDVR0jBBgwFoAUkK9qOpRaC9iQ6hJWc99DtDoo2ucwHQYDVR0OBBYEFHt0yzT4
> NnIfHY3mLUhadPtt7AV8MA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0G
> A1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBPBgNVHSAESDBGMDoGCysGAQQB
> sjEBAgIHMCswKQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNvbW9kby5jb20v
> Q1BTMAgGBmeBDAECATBUBgNVHR8ETTBLMEmgR6BFhkNodHRwOi8vY3JsLmNvbW9k
> b2NhLmNvbS9DT01PRE9SU0FEb21haW5WYWxpZGF0aW9uU2VjdXJlU2VydmVyQ0Eu
> Y3JsMIGFBggrBgEFBQcBAQR5MHcwTwYIKwYBBQUHMAKGQ2h0dHA6Ly9jcnQuY29t
> b2RvY2EuY29tL0NPTU9ET1JTQURvbWFpblZhbGlkYXRpb25TZWN1cmVTZXJ2ZXJD
> QS5jcnQwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAlBgNV
> HREEHjAcggpkdW5nZW9uLmdngg53d3cuZHVuZ2Vvbi5nZzCCAQUGCisGAQQB1nkC
> BAIEgfYEgfMA8QB2AO5Lvbd1zmC64UJpH6vhnmajD35fsHLYgwDEe4l6qP3LAAAB
> ZtXShR0AAAQDAEcwRQIgUpbi64pTttzMStIH1Wa/N2ITGU+w246ykhLeraz9cvsC
> IQCK5UIPxmWQ5uoCoYsATS3EuMgrLYF1ii9a9peK6XP0AQB3AHR+2oMxrTMQkSGc
> ziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABZtXShZUAAAQDAEgwRgIhANnVxzXg9El3
> E9lDysgGU0cq6WhNEaT02aE2OeWxt0vJAiEAnBCG0aoHJpMtrwgxrO9HkWGTWLBC
> iKC5LUqUjmt5yYEwDQYJKoZIhvcNAQELBQADggEBAAt0eDE98avSrz6Ef1BZccTI
> pGQ7UvcdwTlKfWtFI4z7SxsKUvihpYD2bBLE7NyfWFxkNykmBQiR4ptaEe7OT/Ju
> c1LvFPpx7tsEz2LlBGv9L1EK8HWTpCIotMtmmsZpArJh/KNA4yPMh2FEimq7vPhs
> UjfFRKQ4qo7Sb0dF0uQpNc6VjxGNbtNjk/GZ6Efwv920wdjiYU1N2Hnj4hK/e4D5
> BcibsEOu3uDWwa+KuV1/U/03SNGjLTsgPdVC7CaGeXOMSanFtXOF0KDZanMLVZnU
> CcjhaS4Vn8BYGB47ppiEB0eDzyqNdfxqMiaB9JDDG4hePqmfQVorQBvN7fFF7ys=
> -----END CERTIFICATE-----
> subject=/OU=Domain Control Validated/OU=PositiveSSL/CN=dungeon.gg
> issuer=/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
> ---
> No client certificate CA names sent
> Server Temp Key: ECDH, P-384, 384 bits
> ---
> SSL handshake has read 2666 bytes and written 358 bytes
> ---
> New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-GCM-SHA256
> Server public key is 4096 bit
> Secure Renegotiation IS supported
> Compression: NONE
> Expansion: NONE
> No ALPN negotiated
> SSL-Session:
> Protocol : TLSv1.2
> Cipher : ECDHE-RSA-AES128-GCM-SHA256
> Session-ID: 6038753C9F271BE81C5D22DFF4935E5AFECCE16C9FB6EECAEF5B6EE0D37F8908
> Session-ID-ctx: 
> Master-Key: 93CE5931402313B65E0CD9C74A34CD52AF1B152DC03F364B6A8009D434C1A958FDFC6BB0D297608E47B3A3722AD21E4E
> Start Time: 1546388599
> Timeout : 7200 (sec)
> Verify return code: 21 (unable to verify the first certificate)
> ---
> closed
> 
> ```

---

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2019 年1 月 2 日 00:27 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/27 "2019-01-02T00:27:14Z")

</div>

You’re getting the same output as I am

 ![Screenshot%20from%202019-01-02%2008-25-42](https://global.discourse-cdn.com/meta/original/3X/1/9/19f87ba08fd641db3407ffe4db4b574a272735a0.png)

Can you try using the Let’s Encrypt setup instead?

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 00:31 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/28 "2019-01-02T00:31:05Z")

</div>

Yeah, sure! That’s just gonna take me some time. But I honestly thought it would be better to pay for one. 😕

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 01:18 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/29 "2019-01-02T01:18:02Z")

</div>

Done! Getting these returns now:

> **$ openssl s\_client -connect dungeon.gg:443**
>
> ```plaintext
> CONNECTED(00000005)
> depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
> verify return:1
> depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
> verify return:1
> depth=0 CN = dungeon.gg
> verify return:1
> ---
> Certificate chain
> 0 s:/CN=dungeon.gg
> i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
> 1 s:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
> i:/O=Digital Signature Trust Co./CN=DST Root CA X3
> ---
> Server certificate
> -----BEGIN CERTIFICATE-----
> MIIGSzCCBTOgAwIBAgISA9pHO99tl6BBZGjn5r2K1wPgMA0GCSqGSIb3DQEBCwUA
> MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
> ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0xOTAxMDIwMDA4MTdaFw0x
> OTA0MDIwMDA4MTdaMBUxEzARBgNVBAMTCmR1bmdlb24uZ2cwggIiMA0GCSqGSIb3
> DQEBAQUAA4ICDwAwggIKAoICAQChpnWnqhEcBVX82IDSvg/5FuxYBch+Mo2Mc8gj
> dNJVHlWqGLcs7ecj5/544x50wZfSIMPTR3nHfFlpmwCpfwTrJ5IFD/FMzeXasCJE
> 4ZsaCjz9BtyChK1MaLtr5O58SrdfzbWltTADV7CTF7zxhvEoL6SRL3YujbknrY/R
> yUzbHWSte4fLGk1MBDLxEuh0Ee82ds0i4R2kLku/WdyAOUlcMdWwyDD6OT4SibK3
> mbohUVpP3GJCVP/+Qf+F0L8EhvdjRjUppRWqZOz7oeqroytWw0EOdTRN21/vRSlK
> ZjF3uw4py/CbQa3Ok+TrELW6qIMleKwYvFpSe11oKHtOJCLxN0yyEACN5b2CiK/a
> RI3ziQorYnZyLPBKhjXmbK5MaS5BXgSnJw3herpDOnWWw97eGKxS76N9CkCBBFTV
> A+jztwl5wkJvA4fu0s9pOXkfR/SCphMPPuuUGYMSTRmYjxxbEEBPavfPF3yH/6wG
> 8A4kkAr0qIiwarJewIMzxtCrJ0AH4A141WXBPzuvPTOKyZhnaR/8jNS3yl/14og9
> PuUGBmvYd8HcoEtbdFC2wRLMOvmn5OCCPEaYJj1gvv7C2nk+jQNygek1xMzGcVCk
> +UmmXGO6thrxTCHGZWg4f/vWHKoNeXT31GW2ebQtGHa2RuMsYuMCb4sEa1AGDxOR
> a1wRlQIDAQABo4ICXjCCAlowDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsG
> AQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBRs1udBQKZs
> /BgHMTj7vZF1bhQ4LDAfBgNVHSMEGDAWgBSoSmpjBH3duubRObemRWXv86jsoTBv
> BggrBgEFBQcBAQRjMGEwLgYIKwYBBQUHMAGGImh0dHA6Ly9vY3NwLmludC14My5s
> ZXRzZW5jcnlwdC5vcmcwLwYIKwYBBQUHMAKGI2h0dHA6Ly9jZXJ0LmludC14My5s
> ZXRzZW5jcnlwdC5vcmcvMBUGA1UdEQQOMAyCCmR1bmdlb24uZ2cwTAYDVR0gBEUw
> QzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDov
> L2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEDBgorBgEEAdZ5AgQCBIH0BIHxAO8AdQDi
> aUuuJujpQAnohhu2O4PUPuf+dIj7pI8okwGd3fHb/gAAAWgMGp/DAAAEAwBGMEQC
> IBgQgxGzqyhdWrbjk1IP0MzFAyFxxcOl9U/nE/L8m1hcAiAasrGy1K93nW3I5GjN
> UP0wozbQ8MYo9mXnb0I4CTS2VAB2ACk8UZZUyDlluqpQ/FgH1Ldvv1h6KXLcpMMM
> 9OVFR/R4AAABaAwandEAAAQDAEcwRQIhAMRRCh/NqqjeVTjF9okWV5jo5jkXrgfw
> F+XxmKSQbHSBAiA0HCPx7SgcBrQXcyMrvxovGp3/XCwUYwcRsagiY63+XDANBgkq
> hkiG9w0BAQsFAAOCAQEAQK0B79dQbTMe40oXNfMZPl3eYTosZDTUNtofXBaHwNHg
> z7g1hkYuO8BDCR7UVZ8hKmf/1PLn2EQFrPkMrM9e3k8a5sX9LuTa1xaZr1w4BMIi
> Ke4pjS9MD29BYaeEjFzB1yjtqTwBIYRFb+tV9TjdGi77DKc+T0GAZCl37ULGxvtP
> qw6VVJcDYBTcgd8DVyl/B+nerv+LWCpCItA0e+fhpqQ9NTZS+HNsv/C15xqc0Ayk
> tYEK3IFt83x+9NFv+bMCufA3N+a2pHJ2Dg1tTQPqK/L2jebk01jj21gCaayYBhzX
> nEoQPOVviCM7pQOgJHy0gMu4PEPSbosx2ftd/MBtnw==
> -----END CERTIFICATE-----
> subject=/CN=dungeon.gg
> issuer=/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
> ---
> No client certificate CA names sent
> Server Temp Key: ECDH, P-384, 384 bits
> ---
> SSL handshake has read 3587 bytes and written 358 bytes
> ---
> New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-GCM-SHA256
> Server public key is 4096 bit
> Secure Renegotiation IS supported
> Compression: NONE
> Expansion: NONE
> No ALPN negotiated
> SSL-Session:
> Protocol : TLSv1.2
> Cipher : ECDHE-RSA-AES128-GCM-SHA256
> Session-ID: 1E8EF7041BFF50428535FEB1AC1C02AB3B4440C8AFA1ABEB33F82727040DCAC2
> Session-ID-ctx: 
> Master-Key: E857604B095B3379B4D5A16FDE838910893F71E0B37A1C94D65FCA699B873330F199F145A8E269E1218EB913E8947B25
> Start Time: 1546391748
> Timeout : 7200 (sec)
> Verify return code: 0 (ok)
> ---
> closed
> 
> ```

> **$ wget https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png**
>
> ```plaintext
> --2019-01-01 23:17:39-- https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png
> Resolving dungeon.gg (dungeon.gg)... 35.199.105.252
> Connecting to dungeon.gg (dungeon.gg)|35.199.105.252|:443... connected.
> HTTP request sent, awaiting response... 200 OK
> Length: 1730 (1.7K) [image/png]
> Saving to: ‘ea21955a8a3d56191e5d88eb8df873de430f6cb5.png’
> 
> ea21955a8a3d56191e5d88eb8df873de43 100%[================================================================>] 1.69K --.-KB/s in 0s      
> 
> 2019-01-01 23:17:39 (71.7 MB/s) - ‘ea21955a8a3d56191e5d88eb8df873de430f6cb5.png’ saved [1730/1730]
> 
> ```

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2019 年1 月 2 日 01:20 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/30 "2019-01-02T01:20:28Z")

</div>

> [@tgxworld](#):
>
> we want to allow favicons to be served via the CDN.

favicon proxy is actually an opposite problem, see:

> <https://github.com/discourse/discourse/blob/a19170a4c2c37bb6f6ae9531fe4f925777f3e8d5/app/assets/javascripts/discourse.js.es6#L64-L70>

It exists due to this feature:

 ![image](https://global.discourse-cdn.com/meta/original/3X/4/6/46807e480a0570a4d2e5a1c817146376d763e5a0.png)

The `Show new / updated topic count on browser icon` user setting (which is default off) that @chrishunt built back in the day uses canvas to render. The trouble is that canvas has some insane rules here… which I really do not understand.

> **[Use cross-origin images in a canvas - HTML | MDN](https://developer.mozilla.org/en-US/docs/Web/HTML/How_to/CORS_enabled_image)**
>
> HTML provides a crossorigin attribute for images that, in combination with an appropriate CORS header, allows images defined by the element that are loaded from foreign origins to be used in a as if they had been loaded from the current origin.

Basically if you want to render a foreign image in canvas you need to sacrifice a 3 chickens. Because … reasons.

To avoid this we proxy the image locally.

* * *
~~So back on topic... the simplest thing to do here going forward is:
1. Strip this proxy route and logic
 - IF using new favicon scheme simply have the client use “on-site” upload url
 - IF using old scheme then break the feature (favicon notifications) till admins re-upload favicon. (or … maybe you migrate in a onceoff)
 
 ~~

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 01:29 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/31 "2019-01-02T01:29:36Z")

</div>

Guess what?

When you disable `Show new / updated topic count on browser icon` in user preferences, the favicon loads with no problem.

@codinghorror, if you login back again at [https://dungeon.gg](https://dungeon.gg) and disable that option, you can see that it works fine.

It is indeed because of that feature, as @sam pointed out.

For now, I’ll be updating all of my users preferences so that they don’t have that problem. Meanwhile, you guys work on a solution for this.

Again, I’d like to offer help in solving this issue, IF you need it. I’m just now graduating in Computer Science and I really like Discourse and am very enthusiastic about it, so… 🙂

As for the certificate @tgxworld, here are the results, which are now waaaay better: [SSL Server Test: dungeon.gg (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=dungeon.gg)

---

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2019 年1 月 2 日 01:54 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/32 "2019-01-02T01:54:11Z")

</div>

> [@neemiasvf](#):
>
> Meanwhile, you guys work on a solution for this.

There wasn’t anything broken from what I can tell. Your site had SSL incorrectly configured somehow that was preventing us from downloading the image properly as part of the following logic:

> <https://github.com/discourse/discourse/blob/9e508132523313ef9adf6b55830b4c926c0c4fdd/app/controllers/static_controller.rb#L118-L123>

I actually tried to download it manually which is how I noticed that SSL might not have been configured correctly.

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 01:55 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/33 "2019-01-02T01:55:27Z")

</div>

I just now updated all of my user’s preferences by doing:

```plaintext
UserOption.all do |uo|
  uo.set_defaults
  uo.save
end

```

That should solve the problem temporarily.

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 01:57 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/34 "2019-01-02T01:57:06Z")

</div>

Yeah, but even after I changed the configuration to Let’s Encrypt, the problem persisted. The actual solution was changing the setting for `Show new / updated topic count on browser icon` to `false`.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2019 年1 月 2 日 02:00 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/35 "2019-01-02T02:00:24Z")

</div>

> [@neemiasvf](#):
>
> Meanwhile, you guys work on a solution for this.

I am afraid this is impossible. You somehow have a setup where your server is unable to make HTTPS requests to itself.

Run:

```txt
./launcher enter app
rails c
FileHelper.download('https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png')

```

You will notice that does not work cause somehow something is not configured right.

My first recommendation would to do `./launcher rebuild app`, next up I would recommend looking at your Docker DNS settings, maybe somehow DNS is not resolving from when you are inside the container.

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 02:05 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/36 "2019-01-02T02:05:36Z")

</div>

Right.

By running this:

```plaintext
FileHelper.download('https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png')

```

I got:

```plaintext
ArgumentError: missing keywords: max_file_size, tmp_file_name
from /var/www/discourse/lib/file_helper.rb:22:in `download'

```

So I went ahead and ran:

```plaintext
FileHelper.download('https://dungeon.gg/uploads/default/original/1X/ea21955a8a3d56191e5d88eb8df873de430f6cb5.png', max_file_size: 99999, tmp_file_name: 'test')

```

And I got:

```plaintext
=> #<File:/tmp/test20190102-5149-67ou.png>

```

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2019 年1 月 2 日 02:05 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/37 "2019-01-02T02:05:55Z")

</div>

> [@sam](#):
>
> To avoid this we proxy the image locally.

And since our source is going to be on S3 if S3 uploads are enabled, there is nothing we can do.

---

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2019 年1 月 2 日 02:06 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/38 "2019-01-02T02:06:18Z")

</div>

> [@neemiasvf](#):
>
> Yeah, but even after I changed the configuration to Let’s Encrypt, the problem persisted

That is because the favicon is cached for 30 minutes.

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 02:07 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/39 "2019-01-02T02:07:38Z")

</div>

🤔 I see. Anyways, it’s already solved due to changing user’s preferences.

---

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [2019 年1 月 2 日 02:10 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/40 "2019-01-02T02:10:05Z")

</div>

The problem has already been solved by switching to Let’s Encrypt for your SSL needs. You just have to wait 30 mins till the cache is cleared.

---

<div class="post-metadata">

### Author: ![neemiasvf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neemiasvf/32/197028_2.png) [@neemiasvf](https://meta.discourse.org/u/neemiasvf)
#### Post date: [2019 年1 月 2 日 02:12 UTC](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952/41 "2019-01-02T02:12:38Z")

</div>

🤔 Alright. I’ll wait a bit more and change the setting back again. If it works, I’ll give you a 😗 haha

[Previous page](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952.md?page=1)

[Next page](https://meta.discourse.org/t/favicon-is-failing-to-load-for-logged-in-users/104952.md?page=3)
