vSphere HTML Web Client 6.7 SDK自定义插件Virgo服务器报错求助
Absolutely, this is a super common headache for developers building custom plugins for vSphere HTML Web Client 6.7—plenty of folks in the VMware dev community have hit these exact errors. Let’s walk through why this happens and the fixes that have worked for most people:
Common Causes & Solutions
1. Duplicate X-Frame-Headers from Plugin + vCenter
The error message calls out conflicting values (deny, SAMEORIGIN) because two sources are sending the X-Frame-Options header: your custom plugin’s web app, and the vCenter server itself. Virgo’s default config might also be injecting an extra header on top of that.
- Fix: Disable the X-Frame-Options header in your plugin’s code/config. If you’re using a Java-based plugin (standard for Virgo), check your
web.xmlfor any filter that sets this header—comment out or remove that filter definition. For example, if you have a security filter adding<init-param>for X-Frame-Options, delete that line.
2. Virgo’s Built-In Security Header Overrides
Virgo comes with default security settings that automatically add X-Frame-Options headers, which can clash with your plugin’s intended behavior.
- Fix: Tweak the Virgo server’s
tomcat-server.xml(found in[Virgo Installation Directory]/configuration). Look for theHttpHeaderSecurityFiltersection and adjust theantiClickJackingOptionto match vCenter’s expected value (SAMEORIGIN). Here’s how that might look:
You can also disable this filter entirely for your plugin’s context if needed, but matching the value is usually safer.<filter> <filter-name>HttpHeaderSecurityFilter</filter-name> <filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class> <init-param> <param-name>antiClickJackingOption</param-name> <param-value>SAMEORIGIN</param-value> </init-param> </filter>
3. Misconfigured Plugin Manifest
If your plugin’s plugin.xml isn’t correctly declaring its frame context, vCenter might block it from loading in a frame.
- Fix: Double-check your
plugin.xmlextension definitions. Ensure you’re using the correctparentIdfor frame-compatible views (likecom.vmware.vsphere.client.core.views.homeor similar), and verify there are no conflicting permission settings that restrict frame loading.
Quick Post-Fix Checks
- Restart the Virgo server fully after making config changes—partial restarts can leave old settings in place.
- Clear your browser’s cache and cookies before testing, since cached headers can cause the error to persist even after fixes.
- Test with a minimal "hello world" plugin first to rule out complex code in your main plugin causing the conflict.
内容的提问来源于stack exchange,提问作者Bhavya Bansal

