Skip to content
This repository has been archived by the owner on Dec 3, 2020. It is now read-only.

Try to implement "least privilege" for the background iframe #165

Open
groovecoder opened this issue Oct 12, 2018 · 0 comments
Open

Try to implement "least privilege" for the background iframe #165

groovecoder opened this issue Oct 12, 2018 · 0 comments

Comments

@groovecoder
Copy link
Member

The background iframe currently has allow-scripts allow-same-origin allow-forms. Are all of those needed?

Consider reducing the privileges of the iframe sandbox to the bare minimum possible, if they are not already.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants