Add middleware to allow mobile app iframe embedding

Created Django middleware that detects requests from the KeepItGoing
mobile app (via User-Agent) and removes X-Frame-Options header to
allow iframe embedding.

Changes:
- Created tasks/middleware/mobile_app.py with AllowMobileAppFramingMiddleware
- Added middleware to settings after XFrameOptionsMiddleware
- Detects Capacitor WebView User-Agent patterns
- Removes X-Frame-Options only for mobile app, keeps protection for browsers

This allows the mobile app to embed the website in an iframe while
maintaining clickjacking protection for regular web browsers.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
Keith Smith
2025-12-26 22:08:05 -07:00
co-authored by Claude Sonnet 4.5
parent 8db9f99701
commit 31a0c3c8c5
3 changed files with 43 additions and 0 deletions
+1
View File
@@ -44,6 +44,7 @@ MIDDLEWARE = [
'django.contrib.auth.middleware.AuthenticationMiddleware', 'django.contrib.auth.middleware.AuthenticationMiddleware',
'django.contrib.messages.middleware.MessageMiddleware', 'django.contrib.messages.middleware.MessageMiddleware',
'django.middleware.clickjacking.XFrameOptionsMiddleware', 'django.middleware.clickjacking.XFrameOptionsMiddleware',
'tasks.middleware.AllowMobileAppFramingMiddleware', # Allow mobile app iframe embedding
] ]
ROOT_URLCONF = 'config.urls' ROOT_URLCONF = 'config.urls'
+3
View File
@@ -0,0 +1,3 @@
from .mobile_app import AllowMobileAppFramingMiddleware
__all__ = ['AllowMobileAppFramingMiddleware']
+39
View File
@@ -0,0 +1,39 @@
"""
Middleware to allow iframe embedding for the KeepItGoing mobile app.
The mobile app uses Capacitor WebView which embeds the website in an iframe.
This middleware detects requests from the mobile app and removes X-Frame-Options
header to allow iframe embedding, while keeping clickjacking protection for
regular web browsers.
"""
class AllowMobileAppFramingMiddleware:
"""
Remove X-Frame-Options header for requests from KeepItGoing mobile app.
The mobile app uses a Capacitor WebView with a specific User-Agent pattern.
We detect these requests and allow iframe embedding for them.
"""
def __init__(self, get_response):
self.get_response = get_response
def __call__(self, request):
response = self.get_response(request)
# Check if request is from KeepItGoing mobile app
user_agent = request.META.get('HTTP_USER_AGENT', '')
# Capacitor apps include "CapacitorHttp" or the app package name in User-Agent
is_mobile_app = (
'CapacitorHttp' in user_agent or
'com.firebugit.keepitgoing' in user_agent or
'KeepItGoing' in user_agent and 'Mobile' in user_agent
)
# Remove X-Frame-Options for mobile app requests
if is_mobile_app and 'X-Frame-Options' in response:
del response['X-Frame-Options']
return response