Facebook custom tab returns a Forbidden access


Hi to all… First time here (hope to not infringe any rule).

I’ve set up a custom tab on Facebook Developers, which is instructed to show in an IFRAME a certain page laying in my DreamHost-ed website. Something like http[color=#FF0000]s[/color]://www.mywebsite.com/certain/page.shtml (the extension is due to a SSI inside it). At the same time I’ve added through the web panel all the SSL stuff to my domain and I’ve bought a secure certificate, which is now up and running.

Well, when I click on my new tab on Facebook I get a blank iframe with a Forbidden message saying: “You don’t have permission to access /certain/page.shtml on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.”. Needless to say that there is no 404, the page is where it should be: it shows up in all its splendor if I right-click “Show Only This Frame” in Firefox. Sounds like something is preventing Facebook to read my own website.

Permissions are as follows:
/certain/ 755
page.shtml 644

I’m going mad. Please, can you help me?

  1. Use a browser plugin or the like for web developers to look at the request/response headers.
  2. Check the error log for your domain
  3. You might have some sort of mod_security or an .htaccess issue with the referrer header being set


Thanks Atropos7,
Inexplicably, there were no trace of errors in the log. The problem was in the .htaccess, as I have ascertained. After deleting the following, everything runs smoothly:

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^http://www.mywebsite.com [NC]
RewriteRule .* - [F]

order allow,deny
allow from all

lots of denies here…


So wretched the life for the self-taught :frowning:
Thanks again for pointing me there.


A bit more time consuming - but the best way to learn.


Yep! But the problem is, when you learn something that you’ll not put into practice every day, you’ll end up forgetting it. I mean, it was me who put that code in the .htaccess, and now I cannot remember why I did it (I think it was when I was fighting with those p*nis enhancers who were writing in my guestbook). Thanks again for your help. I :heart: DreamHost-ers.