Edit history

Earlier versions of [Self-Hosted] Custom favicon is ignored in initial HTML and `/web/favicon-32x32.png` is used instead, newest first.

Current version | Edited by Rex
Changes
Details### Relation to the previous branding CSP issueRemoved: This appears to be separate from the previous self-hosted branding CSP issue ([#1304](https://feedback.fluxer.com/p/710) / PR [#1651](https://github.com/fluxerapp/fluxer/issues/1651)).Added: This appears to be separate from the previous self-hosted branding CSP issue ([#710](https://feedback.fluxer.com/p/710) / PR [#1651](https://github.com/fluxerapp/fluxer/issues/1651)).That issue concerned configured branding asset origins being blocked by the Content Security Policy. The CSP issue is no longer occurring in this case: the custom favicon URL can be requested successfully and the custom favicon is applied to the browser tab.
Show

[Self-Hosted] Custom favicon is ignored in initial HTML and `/web/favicon-32x32.png` is used instead

Observed behaviour

On a self-hosted instance, a custom favicon configured through Admin Settings → Public App Identity → Favicon URL is correctly stored and exposed through window.__FLUXER_BOOTSTRAP__, but the initial server-rendered HTML still points rel="icon" to the built-in /web/favicon-32x32.png. For example, the bootstrap data correctly contains the configured custom favicon:
"branding": {
  "favicon_url": "https://example.com/assets/branding/favicon.png"
}
However, view-source: for the instance still contains:
<link rel="icon" type="image/png" sizes="32x32" href="https://chat.example.com/web/favicon-32x32.png">
/web/favicon-32x32.png serves the built-in Fluxer favicon rather than the configured custom favicon. The custom favicon does appear in the browser tab after the web app has loaded, so the client appears to apply the configured branding dynamically. However, browser bookmarks/favorites can still use the Fluxer favicon, which is consistent with the initial HTML continuing to advertise /web/favicon-32x32.png. Expected behaviour When favicon_url is configured in Public App Identity, the initial HTML should use that configured URL for rel="icon" instead of the built-in Fluxer favicon. The configured branding value is already present in window.__FLUXER_BOOTSTRAP__, so the setting itself appears to be stored and returned correctly.

Reproduction steps

  1. On a self-hosted Fluxer instance, open Admin Settings → Public App Identity.
  2. Set Favicon URL to a valid custom PNG favicon URL and save the setting.
  3. Confirm that the custom favicon is accessible and that the configured URL appears as branding.favicon_url in window.__FLUXER_BOOTSTRAP__.
  4. Open view-source:https://<instance-domain>/.
  5. Search the initial HTML for rel="icon".
  6. Observe that it still points to /web/favicon-32x32.png rather than the configured favicon_url.
  7. Open /web/favicon-32x32.png directly and observe that it is the built-in Fluxer favicon.
  8. In a browser such as Firefox, bookmark the instance. The tab can display the custom favicon after the app loads, while the bookmark/favorite can still display the built-in Fluxer favicon.

Build information

Stable Web 2026.1003.2520, Linux (x64), Firefox 157.0, Locale en-US

Platform

Web, Self-hosting

Evidence

The following screenshots demonstrate the issue:
  1. Public App Identity configuration showing that a custom Favicon URL is configured.
  2. view-source: / Inspector showing that the initial HTML still contains:
    <link rel="icon" type="image/png" sizes="32x32" href="https://<instance-domain>/web/favicon-32x32.png">
  3. /web/favicon-32x32.png opened directly, showing that this URL serves the built-in Fluxer favicon.
  4. Optionally, a screenshot showing the custom favicon in the browser tab while the saved bookmark/favorite still uses the Fluxer favicon.
The relevant bootstrap data contains the correct configured value:
"branding": {
  "favicon_url": "https://<branding-domain>/assets/branding/favicon.png"
}
while the initial HTML independently contains:
<link rel="icon" type="image/png" sizes="32x32" href="https://<instance-domain>/web/favicon-32x32.png">
The custom branding asset itself is reachable successfully. The previous cross-origin/CSP problem is not reproduced here. For privacy, the instance and branding domains have been redacted from the screenshots/report. The exact hostname does not appear relevant to reproducing the issue.

Details

Relation to the previous branding CSP issue

This appears to be separate from the previous self-hosted branding CSP issue (#710 / PR #1651). That issue concerned configured branding asset origins being blocked by the Content Security Policy. The CSP issue is no longer occurring in this case: the custom favicon URL can be requested successfully and the custom favicon is applied to the browser tab. The remaining issue is specifically that the initial HTML itself still references the built-in Fluxer favicon instead of the configured favicon_url. I am reporting this separately to avoid conflating it with the previous CSP problem or other CSP-related issues.
Original by Rex
Show

[Self-Hosted] Custom favicon is ignored in initial HTML and `/web/favicon-32x32.png` is used instead

Observed behaviour

On a self-hosted instance, a custom favicon configured through Admin Settings → Public App Identity → Favicon URL is correctly stored and exposed through window.__FLUXER_BOOTSTRAP__, but the initial server-rendered HTML still points rel="icon" to the built-in /web/favicon-32x32.png. For example, the bootstrap data correctly contains the configured custom favicon:
"branding": {
  "favicon_url": "https://example.com/assets/branding/favicon.png"
}
However, view-source: for the instance still contains:
<link rel="icon" type="image/png" sizes="32x32" href="https://chat.example.com/web/favicon-32x32.png">
/web/favicon-32x32.png serves the built-in Fluxer favicon rather than the configured custom favicon. The custom favicon does appear in the browser tab after the web app has loaded, so the client appears to apply the configured branding dynamically. However, browser bookmarks/favorites can still use the Fluxer favicon, which is consistent with the initial HTML continuing to advertise /web/favicon-32x32.png. Expected behaviour When favicon_url is configured in Public App Identity, the initial HTML should use that configured URL for rel="icon" instead of the built-in Fluxer favicon. The configured branding value is already present in window.__FLUXER_BOOTSTRAP__, so the setting itself appears to be stored and returned correctly.

Reproduction steps

  1. On a self-hosted Fluxer instance, open Admin Settings → Public App Identity.
  2. Set Favicon URL to a valid custom PNG favicon URL and save the setting.
  3. Confirm that the custom favicon is accessible and that the configured URL appears as branding.favicon_url in window.__FLUXER_BOOTSTRAP__.
  4. Open view-source:https://<instance-domain>/.
  5. Search the initial HTML for rel="icon".
  6. Observe that it still points to /web/favicon-32x32.png rather than the configured favicon_url.
  7. Open /web/favicon-32x32.png directly and observe that it is the built-in Fluxer favicon.
  8. In a browser such as Firefox, bookmark the instance. The tab can display the custom favicon after the app loads, while the bookmark/favorite can still display the built-in Fluxer favicon.

Build information

Stable Web 2026.1003.2520, Linux (x64), Firefox 157.0, Locale en-US

Platform

Web, Self-hosting

Evidence

The following screenshots demonstrate the issue:
  1. Public App Identity configuration showing that a custom Favicon URL is configured.
  2. view-source: / Inspector showing that the initial HTML still contains:
    <link rel="icon" type="image/png" sizes="32x32" href="https://<instance-domain>/web/favicon-32x32.png">
  3. /web/favicon-32x32.png opened directly, showing that this URL serves the built-in Fluxer favicon.
  4. Optionally, a screenshot showing the custom favicon in the browser tab while the saved bookmark/favorite still uses the Fluxer favicon.
The relevant bootstrap data contains the correct configured value:
"branding": {
  "favicon_url": "https://<branding-domain>/assets/branding/favicon.png"
}
while the initial HTML independently contains:
<link rel="icon" type="image/png" sizes="32x32" href="https://<instance-domain>/web/favicon-32x32.png">
The custom branding asset itself is reachable successfully. The previous cross-origin/CSP problem is not reproduced here. For privacy, the instance and branding domains have been redacted from the screenshots/report. The exact hostname does not appear relevant to reproducing the issue.

Details

Relation to the previous branding CSP issue

This appears to be separate from the previous self-hosted branding CSP issue (#1304 / PR #1651). That issue concerned configured branding asset origins being blocked by the Content Security Policy. The CSP issue is no longer occurring in this case: the custom favicon URL can be requested successfully and the custom favicon is applied to the browser tab. The remaining issue is specifically that the initial HTML itself still references the built-in Fluxer favicon instead of the configured favicon_url. I am reporting this separately to avoid conflating it with the previous CSP problem or other CSP-related issues.