Insecure XMLHttpRequest endpoint /badges

(Andrius) #1

Discourse version: v1.9.0.beta7 +174
Using SSL
Using subfolder installation instead of subdomain

Problem occurs when trying to access user details with admin permissions

i have a video reproducing this issue

Issue started appearing after an upgrade.

(Joshua Rosenfeld) #2

Hi @putna,

As can’t reproduce this here on Meta, nor can I reproduce it on my subfolder test site, this is a configuration error with your site.

(Andrius) #3

do you have a clue what configuration could be wrong?

(Joshua Rosenfeld) #4

Well, the usual suspects include:

  • Non-offical plugins
  • Custom JS scripts in site themes
  • NGINX or other proxy in front of site.
  • Abnormal network environment (corporate server with external firewall, for example)

Hard to say exactly what it is unfortunately.