Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
Sandstorm in Docker inside a iframe? #3068
I'm thinking, that if new https://friendup.cloud auth was added (to the existing list of passwordless/LDAP/Google etc), then Sandstorm would be able to run inside iframe in Friend web/desktop/mobile apps in iframe.
Sandstorm intentionally disallows running in an iframe for security reasons -- it would allow clickjacking attacks (where a malicious site renders Sandstorm inside an invisible iframe and tricks you into clicking on it).
Maybe some authentication scheme could be devised to permit Friend, though.
For just Wekan, there is separate friend branch in Wekan repo and docker image, without content-policy, and Wekan password auth will be changed to Friend auth.
Similarly for Sandstorm, there exists passwordless login, Google Auth, GitHub, LDAP and SAML. Friend auth would be added, and Sandstorm used in Docker container, without content-policy.