Problem/Motivation

Hello,
OpenStreetMap tiles don't load anymore on my map, i have 403 http errors.

Proposed resolution

Leaflet should add referrer-policy header when requesting tiles.
https://wiki.openstreetmap.org/wiki/Blocked_tiles
https://github.com/openlayers/openlayers/issues/17088

Comments

quentin massez created an issue. See original summary.

itamair’s picture

Category: Bug report » Support request
Status: Active » Closed (works as designed)
StatusFileSize
new777.62 KB
new792.78 KB
new740.81 KB

Well no, definitely DOES NOT look a Drupal Leaflet module BUG,
but something specifically related to your pages web server setup and requests to OpenstreetMap Tiles.
Probably your specific setup make your browser not sending HTTP Referer.
You should better set your settings and make sure you are complying with OpenstreetMap Tile Usage Policy: https://operations.osmfoundation.org/policies/tiles/

On the Drupal Leaflet module side all looks working fine.
I can’t reproduce the issue you report in some Drupal Leaflet module implementations that I manage, and that are still working fine on the OpenstreetMap tiles, as you can check by yourself:

Drupal Geofield - Leaflet map Demo site:
https://www.geodemocracy.com/drupal_geofield_stack_demo/web/geojson-map-...
Drupal Core: 11.3.4 - PHP: 8.3.30 - Drupal Leaflet: 10.4.4
(screenshot attached showing Referrer set in the HPP Request … )

Taranto-Viva website: https://www.taranto-viva.com
Drupal Core: 11.3.5 - PHP: 8.3.30 - Drupal Leaflet: 10.4.4
Just check and choose the Openstreetmap Layer from the Switcher on the top-right corner
(screenshot attached showing Referrer set in the HPP Request … )

The Way of GODS prototype: https://www.geodemocracy.com/via-degli-dei-2024/web/
Drupal Core: 11.3.5 - PHP: 8.3.30 - Drupal Leaflet: 10.2.43
Just check and choose the Openstreetmap Layer from the Switcher on the top-right corner
(screenshot attached showing Referrer set in the HPP Request … )

Just make sure you are correctly setting and requiring Openstreet Map Tiles layer so as described in the Drupal Leaflet module documentation:
https://git.drupalcode.org/project/leaflet#defining-a-custom-map--hook_l...

and make sure you are not making strange overrides/alters in your server setup Http Requests.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

jonathan_hunt’s picture

fwiw, I had a site with this issue. It turns out I had seckit module enabled with referrer policy set to same-origin. Per advice at https://wiki.openstreetmap.org/wiki/Blocked_tiles#Referer_is_required setting the seckit referrer policy to origin-when-cross-origin meant referer header is sent and OSM is serving tiles ok.

quentin massez’s picture

You were right !!

That was a problem on my website configuration, i had referrer policy same-origin.
I changed it to origin-when-cross-origin and it works !

Thank you to both of you
Regards

michael.acampora’s picture

There are security benefits of setting the referrer to something like same-origin, so would not recommend changing that. Leaflet has the option to set a referrer for retrieving the tiles. That way you only change the referrer for getting some tiles.

You can do something like this:

(function () {
  'use strict';

  if (typeof L !== 'undefined' && L.TileLayer) {
    L.TileLayer.prototype.options.referrerPolicy = 'origin';
  }
})();