The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

The solution of "Lab: Forced OAuth profile linking" will meet issue of "Refused to display 'https://0a2a008e04632038819966d8001a00e0.web-security-academy.net/' in a frame because it set 'X-Frame-Options' to 'sameorigin'."

steven | Last updated: Oct 22, 2024 09:48AM UTC

When I try solution of "Lab: Forced OAuth profile linking", in step 11. I will meet issue of "Refused to display 'https://0a2a008e04632038819966d8001a00e0.web-security-academy.net/' in a frame because it set 'X-Frame-Options' to 'sameorigin'." It looks to me a bug since this http header should not be here. I'm not sure if I misunderstanding something. Thanks.

Ben, PortSwigger Agent | Last updated: Oct 23, 2024 07:44AM UTC

Hi Steven, Are you able to provide us with some more details around the exact steps that you have gone through up until this point for this lab? I have just run through this lab and do not see this issue (I am also able to solve the lab using the written solution and using the embedded browser) so it would be useful to see exactly what you are doing.

steven | Last updated: Oct 29, 2024 03:35AM UTC

Hi Ben, I can't upload any picture here. could you provide a email or other way so I can upload picture to describe more detail.

Ben, PortSwigger Agent | Last updated: Oct 29, 2024 08:25AM UTC