Sandbox iframes to make them secure

Created on 30 May 2025, 6 days ago

Overview

https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/ifr...

- Use the sandbox attribute on our current iframe usages
- Convert any existing cross-frame communications to use postMessage()

Proposed resolution

User interface changes

📌 Task
Status

Active

Version

0.0

Component

Code

Created by

🇺🇸United States hooroomoo

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024