If you use SAMEORIGIN header on hz you need to adjust it.
App::$config['system']['transport_security_header'] = 0;App::$config['system']['content_security_policy'] = 0;App::$config['system']['ssl_cookie_protection'] = 1;
/etc/nginx/conf.d/sub.yourdomain.tld.conf
systemctl restart nginx