Sorry, we don't support your browser.  Install a modern browser

Permission Blocked while embeding Code to a Hostinger website#462

Can you fix this?

Key Issues From Your Errors

CORS Policy Blocks: “Access to fetch at ‘https://kommodo.ai/api/assistant/ready... blocked by CORS policy: No ‘Access-Control-Allow-Origin’ header…”
This means Kommodo.ai is not allowing cross-origin (third-party site) requests from your website, so their service refuses to function inside the iframe.​

Sandboxed iFrame Limitations:
Errors like “service worker is disabled because the context is sandboxed and lacks the ‘allow-same-origin’ flag” indicate that Hostinger is embedding the iframe with restrictions, not permitting it to behave as a “normal” browser tab would. This disables many features the Kommodo.ai embed expects.​

Attribute Precedence Warnings:
“Allow attribute will take precedence over ‘allowfullscreen’” is minor and not related to the failure—you can ignore it.

Firebase/IndexedDB/Remote Config Errors:
These show Kommodo.ai’s code expects to use browser storage, but it’s blocked in your site’s context due to Hostinger’s security setup.​

Permissions Policy Violations:
“autoplay is not allowed”, “fullscreen is not allowed” are consequences of restrictive iframe embedding. They will cause limited functionality but not total failure.

What This Means
The fundamental problem is not with your HTML code, but with:

Kommodo.ai’s server refusing requests from your website (CORS/blocking policies).

Hostinger’s website builder or embedding method enforcing strict iframe sandboxing which blocks nearly everything but basic content display.​

How to Fix or Work Around
Contact Kommodo.ai Support
Request that they allow your site’s domain to embed their content, or ask for a version of their embed that supports locked-down website builders.​

Contact Hostinger Support
Ask if they allow configuring iframes to relax sandboxing (allow-same-origin, allow-scripts) or to allow cross-domain embeds. If not, request a workaround or clarification on supported embed scenarios.​

Technical Workarounds (If Possible)

If you can edit your site’s underlying HTML (not just embed code), you could try embedding the iframe without sandboxing—but most site builders don’t allow this.

If you have access to a VPS or more advanced hosting, consider manually creating a page (outside the builder) that can set appropriate iframe attributes.

Alternative Approaches

If Kommodo.ai cannot be embedded, consider linking directly to their hosted recording instead of embedding.

Summary Table (see image)

In summary: Only Hostinger and Kommodo.ai can resolve this, as it’s due to their security setups—not a code change you can make yourself. You must contact their support teams, provide these exact errors, and ask about embedding and sandboxing restrictions.

8 months ago

Hi, where are you getting this CORS error? What are you doing at this moment?

8 months ago

I’m getting these errors. Can you fix it? index-1762952791169.js:56 Allow attribute will take precedence over ‘allowfullscreen’.
RQ @ index-1762952791169.js:56Understand this warning
about:srcdoc:19 Allow attribute will take precedence over ‘allowfullscreen’.Understand this warning
0eJDa3VqTMh936t6rF3k?onlyRecording=1:271 A preload for ‘https://uploads-wnam-prod-cdn.komododecks.com/kpYMfTFsrvdoEjk2BlnDGI1Yn5u1/0eJDa3VqTMh936t6rF3k/image.jpg?verify=1762977234-9r0YoDDm9FsZg25L5sijvrlG6AC_u-atDhXL6xLoBck=' is found, but is not used because the request credentials mode does not match. Consider taking a look at crossorigin attribute.Understand this warning
4vendors-08202630f5603045.js:41 Uncaught (in promise) FirebaseError: Remote Config: Error thrown when opening storage. Original error: Failed to execute ‘open’ on ‘IDBFactory’: access to the Indexed Database API is denied in this context.. (remoteconfig/storage-open).
at C.appId (vendors-08202630f5603045.js:41:38357)
at new Promise (<anonymous>)
at new C (vendors-08202630f5603045.js:41:38086)
at i.instanceFactory (vendors-08202630f5603045.js:41:42256)
at s.getOrInitializeService (vendors-08202630f5603045.js:1339:34496)
at s.getImmediate (vendors-08202630f5603045.js:1339:32435)
at i.P [as instanceFactory] (vendors-08202630f5603045.js:41:43793)
at s.getOrInitializeService (vendors-08202630f5603045.js:1339:34496)
at s.getImmediate (vendors-08202630f5603045.js:1339:32435)
at p._getService (vendors-08202630f5603045.js:12:158812)
at e.<computed> [as remoteConfig] (vendors-08202630f5603045.js:12:160091)
at Object.a [as remoteConfig] (vendors-08202630f5603045.js:12:159968)
at _app-09866c5a471023a0.js:1:37641
at 34320 (_app-09866c5a471023a0.js:1:37798)
at a (webpack-b196ab509b7b7f94.js:1:526)
at 32473 (_app-09866c5a471023a0.js:1:36177)
at a (webpack-b196ab509b7b7f94.js:1:526)
at 56380 (_app-09866c5a471023a0.js:1:77281)
at a (webpack-b196ab509b7b7f94.js:1:526)
at 81829 (_app-09866c5a471023a0.js:1:110949)
at a (webpack-b196ab509b7b7f94.js:1:526)
at _app-09866c5a471023a0.js:1:530
at vendors-08202630f5603045.js:1339:48163Understand this error
1050-ebeb4c28de083348.js:1 Allow attribute will take precedence over ‘allowfullscreen’.
p @ 1050-ebeb4c28de083348.js:1Understand this warning
2vendors-08202630f5603045.js:5 SecurityError: Failed to read the ‘serviceWorker’ property from ‘Navigator’: Service worker is disabled because the context is sandboxed and lacks the ‘allow-same-origin’ flag.
at _app-09866c5a471023a0.js:1:35111
at sF (vendors-08202630f5603045.js:1:201089)
at aU (vendors-08202630f5603045.js:1:230082)
at vendors-08202630f5603045.js:1:224657
at S (vendors-08202630f5603045.js:41:125434)
at MessagePort.O (vendors-08202630f5603045.js:41:125964)
(anonymous) @ vendors-08202630f5603045.js:5Understand this error
vendors-08202630f5603045.js:5 A client-side exception has occurred, see here for more info: https://nextjs.org/docs/messages/client-side-exception-occurred
(anonymous) @ vendors-08202630f5603045.js:5Understand this error
js:1

8 months ago

Failed to load resource: net::ERR_NAME_NOT_RESOLVEDUnderstand this error
vendors-08202630f5603045.js:5 [Rewardful] Cookie ‘rewardful.referral’ is not valid JSON.
(anonymous) @ vendors-08202630f5603045.js:5Understand this warning
vendors-08202630f5603045.js:5 Rewardful failed to initialize: SecurityError: Failed to set the ‘cookie’ property on ‘Document’: The document is sandboxed and lacks the ‘allow-same-origin’ flag.
(anonymous) @ vendors-08202630f5603045.js:5Understand this error
0eJDa3VqTMh936t6rF3k?onlyRecording=1:1 Access to fetch at ‘https://kommodo.ai/api/assistant/ready?senderId=kpYMfTFsrvdoEjk2BlnDGI1Yn5u1&presentationId=0eJDa3VqTMh936t6rF3k&presentationDate=' from origin ‘null’ has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: No ‘Access-Control-Allow-Origin’ header is present on the requested resource.Understand this error
kommodo.ai/api/assistant/ready?senderId=kpYMfTFsrvdoEjk2BlnDGI1Yn5u1&presentationId=0eJDa3VqTMh936t6rF3k&presentationDate=:1 Failed to load resource: net::ERR_FAILEDUnderstand this error
vendors-08202630f5603045.js:5 Assistant Status Error: TypeError: Failed to fetch
at vendors-08202630f5603045.js:19:53796
at 8411-6eed4453dac2f210.js:1:119998
at 8411-6eed4453dac2f210.js:1:120352
at sF (vendors-08202630f5603045.js:1:201089)
at aU (vendors-08202630f5603045.js:1:230082)
at vendors-08202630f5603045.js:1:224657
at S (vendors-08202630f5603045.js:41:125434)
at MessagePort.O (vendors-08202630f5603045.js:41:125964)
(anonymous) @ vendors-08202630f5603045.js:5Understand this error
[Violation] Potential permissions policy violation: autoplay is not allowed in this document.Understand this error
[Violation] Potential permissions policy violation: fullscreen is not allowed in this document.Understand this error
2vendors-08202630f5603045.js:5 SecurityError: Failed to read the ‘serviceWorker’ property from ‘Navigator’: Service worker is disabled because the context is sandboxed and lacks the ‘allow-same-origin’ flag.
at _app-09866c5a471023a0.js:1:35111
at sF (vendors-08202630f5603045.js:1:201089)
at aU (vendors-08202630f5603045.js:1:230082)
at vendors-08202630f5603045.js:1:224657
at S (vendors-08202630f5603045.js:41:125434)
at MessagePort.O (vendors-08202630f5603045.js:41:125964)
(anonymous) @ vendors-08202630f5603045.js:5Understand this error
vendors-08202630f5603045.js:5 A client-side exception has occurred, see here for more info: https://nextjs.org/docs/messages/client-side-exception-occurred
(anonymous) @ vendors-08202630f5603045.js:5Understand this error
8The resource <URL> was preloaded using link preload but not used within a few seconds from the window’s load event. Please make sure it has an appropriate as value and it is preloaded intentionally.

8 months ago