We have made a security change to the platform. Pages on sporty.co.nz and schoolground.co.nz can no longer be loaded inside a frame or iframe on another website. If a third-party site tries to embed a page from Sporty, the page will show as blank or as an error.
For the vast majority of organisations this changes nothing at all. Your site, your draws and results, your forms and your member pages all work exactly as they did.
Why we have done this
There is a well-known attack on the web called clickjacking. A malicious website loads a real page, in this case one of yours, inside a hidden or transparent frame and lays its own content over the top. You think you are clicking a button on their page, but the click actually lands on ours. If you happen to be logged in to your organisation at the time, that click can do real things on your behalf: submit a form, change a setting, approve a payment, or delete content.
The person clicking has no way of knowing it happened. Nothing looks wrong, which is exactly what makes the attack effective.
Allowing any website in the world to frame your pages also meant we could not guarantee where your content was being displayed, or what was being layered over it.
This is the recognised standard defence
Restricting who may frame your pages is the control the security industry recommends for this. It is not a workaround or something we have invented.
The OWASP Clickjacking Defence Cheat Sheet, the most widely used reference for web application security worldwide, is explicit that sites should block framing by default "unless a specific need has been identified for framing". OWASP also recommends a defence in depth approach, using several layers together rather than relying on any single one, which is what we have implemented.
The mechanism itself is part of the W3C's Content Security Policy Level 2 specification, an open web standard supported by every major browser. It is the same control used by banks, government services and every serious SaaS platform. Security scanners and penetration testers routinely flag its absence as a vulnerability, so putting it in place also strengthens the security posture we can demonstrate to the sports organisations, schools and partners who rely on the platform.
What to do if you were framing a Sporty page in another website
A small number of organisations run a separate website of their own (WordPress, Squarespace, Wix and similar) and had embedded a Sporty page into it. That embed will no longer display.
The fix is to link to the Sporty page rather than frame it. Add a normal link or button on your site pointing at the Sporty page URL. Visitors click through and see the content from Sporty as intended, with everything working properly on mobile as well. In most cases this is a better experience anyway, since framed pages tend to scroll and size badly on phones.
If linking out genuinely does not work for your situation, get in touch with our support team and tell us what you are trying to achieve. We will work through the options with you.
A note on the Draws & Results widget
If you display draws and results on your Sporty site using the Draws & Results widget, nothing changes for you. The widget sits inside your Sporty site, so it is unaffected. See Adding and Setting the Draws & Results Widget if you have not set it up yet.
Questions?
Flick us a note at support@sportsground.com and we will help you sort it.