HubX host simulator

S4-24562 · stands in for HubX's page, from a genuinely cross-site origin · throwaway diagnostic

What this is for. The dev harness in apps/web/vite/embedHarness.ts frames the embed from localhost, which is same-origin and therefore proves nothing about how a real third-party host is treated. This page is that host.

Read the headers panel before believing the frame. A frame refused by x-frame-options or frame-ancestors looks identical to a 404 or a crash from out here — the browser tells the embedder nothing, by design. The headers panel asks the server directly (via a Pages Function, which is not bound by CORS) so a refusal is legible instead of looking like an empty box.
Target

The frame

not run yet

Response headers (server-side)

not run yet
—

postMessage from the frame

nothing yet