Sep 26, 2018



We have an LTI integration that works in a staging environment running Release 3300.0.4-rel.65+9afd532. In production, we’re running Release 3300.0.3-rel.41+a9e64de, but the identical setup in staging, won’t work in production.


We’ve built an LTI integration that takes us to an external application. In production, we get the following error:


Refused to display '' in a frame because it set 'X-Frame-Options' to 'sameorigin’.


We had a fix deployed in staging that fixed the cross origins issue we see in this error, but the same fix just won’t work in the production environment. So we’re not sure if this error is in fact the issue, or just a by product of something else.


When we look at the URL itself, we’re noticing a contentwrapper.jsp being applied in production, which seems to be preventing the LTI from opening, and what we suspect is triggering the cross origins. You can see for example:


This URL structure works fine, when we strip the contentwrapper from it:


But, Blackboard seems to be applying it by default, or it’s a setting somewhere that we can’t figure out, that turns the URL to:


So we’re wondering if there is some global setting that’s turning on this contentwrapper, or if we’re missing something in the LTI config itself…