VPN software blocking https://js.braintreegateway.com/
See original GitHub issueGeneral information
- SDK version: N/A
- Environment: Production
- Browser and OS : NordVPN
Issue description
We occasionally have customers that say the hosted forms control does not come up. One customer with this problem claims to be using NordVPN and that disabling it allowed them to continue.
I just installed it myself (default install on Windows 10) and it does in fact block the js.braintreegateway.com domain in both Chrome & Edge. I did not change any settings. And yes toggling it off immediately allows the domain to be accessed.
https://js.braintreegateway.com/web/3.68.0/js/hosted-fields.js **BLOCKED**
https://www.braintreegateway.com/ **NOT BLOCKED**
Interestingly (and I’m no VPN expert) the way it seems to route traffic to 127.0.0.1
and I know this because it served my own developer certificate to me when I access the link above. In Chrome it is just a failed request:
Presumably this would need to be addressed as a whitelisting process between Braintree and NordVPN.
The following screenshots are with the VPN active:
Workaround
Can you confirm that hosted fields functionality is not impacted if I just serve the JS locally myself. I have no idea how many people are using such a VPN service - I may just to retry and fetch a local version if I get a script error, but still benefit from your CDN for the majority of people.
Issue Analytics
- State:
- Created 3 years ago
- Comments:9 (5 by maintainers)
Top GitHub Comments
Hosting locally is working fine.
Another domain being blocked by the VPN is (not surprisingly)
https://client-analytics.braintreegateway.com
but I was able to submit a nonce to my server for a credit card just fine 😃Turns out a few other things are being blocked, including our cookie consent provider. It’s privacy working against privacy 😕
I’ve configured mine as a fallback, so I’ll report back how many users a day are on VPN (or have another failure accessing your hosted JS).
Shoot I just literally cancelled and uninstalled it late last night! But I made sure to give your URL when the support agent asked why I was cancelling!
The percentage of failures is dropping closer to half a percent of users when it was quite high at close to 1% a week ago. I’ll reset the counter and report back again in a few days.
On Mon, Jan 18, 2021 at 8:51 AM Blade Barringer notifications@github.com wrote: