amplitude / amplitude/Amplitude-TypeScript

Session Replay Plugin causes a "Blocked a frame with origin "https://mysite.com" from accessing a frame with origin "https://vendor.site" on Mac Safari

Ouverte
#1,248 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
bug
Langage dominant
TypeScript
Étoiles
180
Forks
68
Merge moyen
3 j 1 h
PR mergées (30 j)
29

Description

When session replay is enabled, and a iframe is rendered on Mac Safari browser, a "blocked frame" error (per the title) appears, e.g.:

[Error] Blocked a frame with origin "https://localhost:3000" from accessing a frame with origin "https://js.stripe.com". Protocols, domains, and ports must match.
serializeNodeWithId (rrweb-record-7RRQZYYR.js:1166)
serializeNodeWithId (rrweb-record-7RRQZYYR.js:1249)
serializeNodeWithId (rrweb-record-7RRQZYYR.js:1249)
serializeNodeWithId (rrweb-record-7RRQZYYR.js:1249)
takeFullSnapshot$1 (rrweb-record-7RRQZYYR.js:12032)
init (rrweb-record-7RRQZYYR.js:12220)
record (rrweb-record-7RRQZYYR.js:12225)
(anonymous function) (@amplitude_plugin-session-replay-browser.js:4148)
step (chunk-JKUCZERB.js:125)
fulfilled (chunk-JKUCZERB.js:49)

I tried all sorts of ways to block session replay using the privacyConfig.blockSelector, but none work, probably due to the way iframes are injected into the page.

Is there a way to block specific iframes by provider (e.g. stripe, firebase) via configuration that I'm missing?

Btw, Sentry (which also uses rrweb for session recording) used to have the [same issue](https://github.com/getsentry/rrweb/pull/240). It looks like they handled the issue by not attaching load event listeners to block blocked frames.

My environment:
- Most current Safari, React, Amplitude and Stripe versions as of August 2025.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.