# Whitelist referer for web embeds http referer x frame options?

**URL:** <https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422>\
**Category:** Ask for Help\
**Created:** [April 11, 2023, 6:35pm UTC](https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422 "2023-04-11T18:35:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sidney\_Kunst](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/sidney_kunst/32/603_2.png) [@Sidney\_Kunst](https://community.glideapps.com/u/Sidney_Kunst)\
**Post date:** [April 11, 2023, 6:35pm UTC](https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422/1 "2023-04-11T18:35:15Z")

</div>

Hi there,

I’m struggling with which domain i should whitelist to allow my website to embed to.

So embedding a website in the glide app, and the glide app only (exclusively)

I want to add this in the .htaccess of a website. But it won’t work.  
I tried glide. page  
glideapps. io  
glideapps. com

But none of them work. Which domain should i allow? This is the code i’m using:

RewriteEngine on

RewriteCond %{HTTP\_REFERER} !^https://(www.)?glideapp.io/ [NC]

RewriteCond %{REQUEST\_URI} !^/wp-admin [NC]

RewriteRule ^(.\*)$ [https://google.com/$1](https://google.com/$1) [L,R=301]

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [April 12, 2023, 12:28am UTC](https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422/2 "2023-04-12T00:28:47Z")

</div>

@Jason @Daniel_Sweet Can you help with this? Thanks a lot.

---

<div class="post-metadata">

**Author:** ![Sidney\_Kunst](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/sidney_kunst/32/603_2.png) [@Sidney\_Kunst](https://community.glideapps.com/u/Sidney_Kunst)\
**Post date:** [April 13, 2023, 8:17am UTC](https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422/3 "2023-04-13T08:17:41Z")

</div>

FOUND IT!!  
referer is [https://go.glideapps.com/](https://go.glideapps.com/)

so code should be:

RewriteEngine on

RewriteCond %{HTTP\_REFERER} !^https://([www.)?go.glideapps.com/.\*](http://www.%29/?go.glideapps.com/.*) [NC]  
RewriteCond %{REQUEST\_URI} !^/wp-admin [NC]  
RewriteRule ^(.\*)$ [https://google.com](https://google.com) [L,R=301]

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [April 13, 2023, 8:24am UTC](https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422/4 "2023-04-13T08:24:55Z")

</div>

I’m surprised that works.  
`go.glideapps.com` is the builder URL…  
But hey, if it works, that’s great

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/system/32/53398_2.png) [@system](https://community.glideapps.com/u/system)\
**Post date:** [April 14, 2023, 8:25am UTC](https://community.glideapps.com/t/whitelist-referer-for-web-embeds-http-referer-x-frame-options/60422/5 "2023-04-14T08:25:40Z")

</div>

This topic was automatically closed 24 hours after the last reply. New replies are no longer allowed.
