# Form embed script missing the https:

**URL:** <https://forum.mautic.org/t/form-embed-script-missing-the-https/6468>\
**Category:** Product Support\
**Created:** [November 7, 2016, 2:28pm UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468 "2016-11-07T14:28:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alanorourke](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@alanorourke](https://forum.mautic.org/u/alanorourke)\
**Post date:** [November 7, 2016, 2:28pm UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468/1 "2016-11-07T14:28:19Z")

</div>

Anyone know why this form embed URL is wrong?  
  
Brand new Mautic install and I got excited and wanted to try and create a website form and see it working ![:)]( ":)")  
  
  
  
I have created the form and when I try to embed it on my site you can see here the URLs in the embed scripts are wrong.  
  
[https://www.dropbox.com/s/r1zcz5bv1xl2j78/mautic-forms.png?dl=0](https://www.dropbox.com/s/r1zcz5bv1xl2j78/mautic-forms.png?dl=0)  
  
  
  
Does anyone know why? Did I miss a setting configuration?  
  
  
  
Thanks,  
  
Alan

---

<div class="post-metadata">

**Author:** ![alanorourke](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@alanorourke](https://forum.mautic.org/u/alanorourke)\
**Post date:** [November 7, 2016, 2:28pm UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468/2 "2016-11-07T14:28:19Z")

</div>

Anyone know why this form embed URL is wrong?  
Brand new Mautic install and I got excited and wanted to try and create a website form and see it working 🙂

I have created the form and when I try to embed it on my site you can see here the URLs in the embed scripts are wrong.  
[https://www.dropbox.com/s/r1zcz5bv1xl2j78/mautic-forms.png?dl=0](https://www.dropbox.com/s/r1zcz5bv1xl2j78/mautic-forms.png?dl=0)

Does anyone know why? Did I miss a setting configuration?

Thanks,  
Alan

---

<div class="post-metadata">

**Author:** ![ninjoan](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ninjoan/32/1005_2.png) [@ninjoan](https://forum.mautic.org/u/ninjoan)\
**Post date:** [November 7, 2016, 6:23pm UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468/3 "2016-11-07T18:23:39Z")

</div>

@alanorourke is ok will works 🙂

---

<div class="post-metadata">

**Author:** ![alanorourke](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@alanorourke](https://forum.mautic.org/u/alanorourke)\
**Post date:** [November 8, 2016, 9:28am UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468/4 "2016-11-08T09:28:02Z")

</div>

Thank you Ninjoan, You are right. I have never seen that before 🙂

However the iframe form still does not display and on the javascript form the asset does not download. The button just hangs on “Please wait…”

Test page is at [https://www.onepagecrm.com/test-mautic-form-page](https://www.onepagecrm.com/test-mautic-form-page)

Any ideas?

Thank you.

---

<div class="post-metadata">

**Author:** ![MarkLL](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@MarkLL](https://forum.mautic.org/u/MarkLL)\
**Post date:** [November 8, 2016, 11:57am UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468/5 "2016-11-08T11:57:06Z")

</div>

Hi @alanorourke If you view the Security properties for the page (in chrome) this come up…

```auto
Refused to display 'https://onepagemkt.com/form/1' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN'.
```

and

```auto
XMLHttpRequest cannot load https://onepagemkt.com/mtc. Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'https://www.onepagecrm.com' is therefore not allowed access.
```

Not having progressed passed the testing phase at this stage, I can’t really offer much advise, but but check the Settings / Configuration / CORS Settings. It seems that the default is to restrict the domains.

Edit: I was snooping round the Middleware code yesterday and in CORSMiddleware.php it checks for an OPTIONS request and returns a valid response only if `requestOriginIsValid`. In other words, what I said above should work. You could try putting in [https://www.onepagecrm.com](https://www.onepagecrm.com) into the Valid Domains text box.

---

<div class="post-metadata">

**Author:** ![alanorourke](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@alanorourke](https://forum.mautic.org/u/alanorourke)\
**Post date:** [November 8, 2016, 4:56pm UTC](https://forum.mautic.org/t/form-embed-script-missing-the-https/6468/6 "2016-11-08T16:56:41Z")

</div>

Thank you MarkLL for pointing me in the right direction.  
The security restriction was on the server itself not Mautic. All working now 🙂

Alan
