# Worldmap - access blocked, error r403

**URL:** <https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759>\
**Category:** General\
**Tags:** windows, node-red-contrib-web-worldmap\
**Created:** [12 April 2026 18:02 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759 "2026-04-12T18:02:57Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [12 April 2026 18:02 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/1 "2026-04-12T18:02:57Z")

</div>

I've just installed [Node.js v20](https://github.com/vladimir-andreevich/node.js-windows-7/tree/main/v20) + latest stable NodeRed **v4.1.8** successfully on Windows **7** 32bit OS.  
I'm getting [this 403r error](https://wiki.openstreetmap.org/wiki/Blocked_tiles#If_you_are_the_owner/a_developer_of_the_application/website) on the map:

 ![kép](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/e/5e2ab51cde2a2abccd6aab8f3ede2239630a5fae.jpeg)

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [12 April 2026 19:52 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/2 "2026-04-12T19:52:54Z")

</div>

What about other base maps ?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 April 2026 20:02 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/3 "2026-04-12T20:02:48Z")

</div>

> [@PizzaProgram](#):
>
> Windows **7** 32bit OS

Just a side-note that this is playing with fire. A dangerous OS to have connected to the Internet in the 2020's.

---

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [12 April 2026 20:22 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/4 "2026-04-12T20:22:08Z")

</div>

You are right, all the other maps I've checked working well,  
only OSM is problematic.  
But sadly OSM is what users will use mostly.

 ![kép](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/5/d590b2c601e4d1c1ca4fb381776c9f566ab460ba.png)

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [12 April 2026 20:24 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/5 "2026-04-12T20:24:05Z")

</div>

Good. I’ll have a look next week.

---

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [12 April 2026 20:35 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/6 "2026-04-12T20:35:44Z")

</div>

# OFF

> [@TotallyInformation](#):
>
> Just a side-note that this is playing with fire. A dangerous OS to have connected to the Internet in the 2020's.

This is not the right topic for that, but as I've stated many many times in all forums already:

# Fact is:

- `>60 %` of my users are still using Win7 daily 16+ hours 360/365, **without any problems!** _(100+ POS configured PCs in restaurants.)_
- While we have problems with Win10 64bit PCs **every week**!  
_(Even work-breaking, shop force-closing kind of big problems.)_

IMHO an OS's security level is mostly dependent: **how it's configured** ,  
_(All unnecessary services disabled, proper Firewall settings, no Admin rights to users, etc.)_

"Newer" does not necessarily means "better".

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [12 April 2026 20:54 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/7 "2026-04-12T20:54:40Z")

</div>

> [@PizzaProgram](#):
>
> But sadly OSM is what users will use mostly.

You can of course hide it from the options to set another default for your users. Hopefully this is also reproducible for me and there is a fix we can apply to get them back online.

---

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [12 April 2026 21:47 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/8 "2026-04-12T21:47:33Z")

</div>

I'm trying to find out myself, but I'm not a web-developer.  
If I press F12 in Firefox, there are many warning listed, but no blocking errors.

It's probably not related but found a tiny bug at the function of 541. line:  
_(heatmap is turned off)_

```js
// Remove old markers
function doTidyUp(l) {
    if (l === "heatmap") {
        heat.setLatLngs([]); // << HERE is the problem!

(TypeError: heat is undefined
    doTidyUp worldmap.js:544

```

## List of Warnings:

```tex
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/sockjs.min.js
Forrástérkép webcíme: sockjs.min.js.map

A MouseEvent.mozPressure absolute. Használja helyette a PointerEvent.pressure tulajdonságot. Util.js:27:2

Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/VectorTileLayer.umd.min.js
Forrástérkép webcíme: VectorTileLayer.umd.min.js.map

Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/leaflet-rotate.js
Forrástérkép webcíme: leaflet-rotate.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/togeojson.umd.js
Forrástérkép webcíme: togeojson.umd.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/leaflet.antimeridian-src.js
Forrástérkép webcíme: leaflet.antimeridian-src.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/sockjs.min.js
Forrástérkép webcíme: sockjs.min.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/pmtiles.js
Forrástérkép webcíme: pmtiles.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/sockjs.min.js
Forrástérkép webcíme: sockjs.min.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/esri-leaflet.js
Forrástérkép webcíme: esri-leaflet.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/sockjs.min.js
Forrástérkép webcíme: sockjs.min.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/VectorTileLayer.umd.min.js
Forrástérkép webcíme: VectorTileLayer.umd.min.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/leaflet.antimeridian-src.js
Forrástérkép webcíme: leaflet.antimeridian-src.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/leaflet-rotate.js
Forrástérkép webcíme: leaflet-rotate.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/sockjs.min.js
Forrástérkép webcíme: sockjs.min.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/pmtiles.js
Forrástérkép webcíme: pmtiles.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/togeojson.umd.js
Forrástérkép webcíme: togeojson.umd.js.map
Source map error: Error: request failed with status 404
Resource URL: http://localhost:1880/wm/leaflet/esri-leaflet.js
Forrástérkép webcíme: esri-leaflet.js.map

```

* * *

Source map error links: [Source map errors — Firefox Source Docs documentation](https://firefox-source-docs.mozilla.org/devtools-user/debugger/source_map_errors/?utm_source=mozilla&utm_medium=firefox-console-errors&utm_campaign=default)

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 April 2026 04:22 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/9 "2026-04-13T04:22:09Z")

</div>

It's unlikely you find that error in the browser console.

The server side is simply blocking HTTP requests that miss the `Referer` header. Which is not uncommon, so these images can't be directly be linked from external sites (which causes extra traffic, can be misused, etc...).

For "normal" website browsing, the referer is set by the browser, e.g. when you click a link, the referer is set to the originating site.

So it depends on how OSM loads these tiles, I guess via some JS. So that's where I'd start looking to set that header.

Some hints are documented on their wiki:

> **[Blocked tiles - OpenStreetMap Wiki](https://wiki.openstreetmap.org/wiki/Blocked_tiles)**

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [13 April 2026 08:39 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/10 "2026-04-13T08:39:10Z")

</div>

The error you showed in your first post includes a link to the section of the wiki describing the problem and what needs to be done to sort it.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [13 April 2026 13:22 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/11 "2026-04-13T13:22:16Z")

</div>

From the wiki:

> If the tile mentions "_Referer is required_" then you were automatically blocked because your application/website is not sending HTTP `Referer` headers, but doing so is required by the tile usage policy. This block will resolve itself once you make the necessary changes to your application, without further intervention necessary.
> 
> For websites/web applications, this can be fixed by setting your `Referrer-Policy` header to any of `no-referrer-when-downgrade`, `origin`, `origin-when-cross-origin`, `strict-origin`, or `strict-origin-when-cross-origin`.
> 
> For more information, see the [Referer](https://wiki.openstreetmap.org/wiki/Referer) article.

I think you should be able to set the `Referrer-Policy` header in Node-RED's settings.js file. Or, if you are using a reverse proxy to protect outbound traffic, set it in the proxy.

---

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [14 April 2026 09:31 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/12 "2026-04-14T09:31:56Z")

</div>

> [@TotallyInformation](#):
>
> For more information, see the [Referer](https://wiki.openstreetmap.org/wiki/Referer) article.

Thank you very much for this link !  
It has led me to a leaflet Github issue about this problem, including [^ this (link)](https://github.com/Leaflet/Leaflet/pull/9883#issuecomment-3312085163) post.

That gave me an idea, that maybe there is a browser plugin, that may interfere...

SOLVED.

---

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [14 April 2026 09:39 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/13 "2026-04-14T09:39:01Z")

</div>

# [SOLVED]

I just had to fine-adjust uBlock origin plugin in my Firefox browser (`v115.34.1esr 32bit`), and the problem is gone!

- Simply allow "1st-party scripts" !
- or **un** block that site you are using with WorldMap (big blue On/Off icon)

 ![kép](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/c/ccbb1788442919ff3e74ec44c001844c75527fb0.jpeg)

It is possible, that the root of this problem was, that I'm using the map via **localhost** http. (no http **s** )  
[http://localhost:1880/wm/](http://localhost:1880/wm/)

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [14 April 2026 11:40 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/14 "2026-04-14T11:40:59Z")

</div>

Good find. Well done !  
I always forget to ask users about plugins they may installed 🙂

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [14 April 2026 18:42 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/15 "2026-04-14T18:42:05Z")

</div>

> [@PizzaProgram](#):
>
> That gave me an idea, that maybe there is a browser plugin, that may interfere...

Which is why I have a browser profile with no addins. 😃

In fact I keep dev and other browsing in separate profiles as well and something separate for risky social media so that I can keep proper separation between different purposes. This really helps keep things like cookies in separate containers.

---

<div class="post-metadata">

**Author:** ![PizzaProgram](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/pizzaprogram/32/19431_2.png) [@PizzaProgram](https://discourse.nodered.org/u/PizzaProgram)\
**Post date:** [16 April 2026 01:41 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/16 "2026-04-16T01:41:20Z")

</div>

Did you succeed to fix the:

```js
heat.setLatLngs([])

```

[^ problem](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/8) when heatmap is turned off?  
_(Also the corresponding caller routines, if they get a null as return?)_

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [30 April 2026 01:41 UTC](https://discourse.nodered.org/t/worldmap-access-blocked-error-r403/100759/17 "2026-04-30T01:41:21Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
