You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have a use case where a user can provide the URL of a site, which will then be loaded into a sandboxed iframe. I was testing this a bit and found that, even though no 'allow-download' flag was set, the user still could trigger a download by providing a URL pointing directly to a downloadable file (e.g. https://download.mozilla.org/?product=firefox-stub&os=win&lang=en-US). The download triggered in multiple different browsers and I searched through the documentation about iframes but could not find anything related to this specific case.
Can someone please tell me if this is intended behavior?
The text was updated successfully, but these errors were encountered:
I have a use case where a user can provide the URL of a site, which will then be loaded into a sandboxed iframe. I was testing this a bit and found that, even though no 'allow-download' flag was set, the user still could trigger a download by providing a URL pointing directly to a downloadable file (e.g. https://download.mozilla.org/?product=firefox-stub&os=win&lang=en-US). The download triggered in multiple different browsers and I searched through the documentation about iframes but could not find anything related to this specific case.
Can someone please tell me if this is intended behavior?
The text was updated successfully, but these errors were encountered: