[webkit-dev] Review of patch to support iframe's allow-popups-to-escape-sandbox?

Frédéric WANG fred.wang at free.fr
Wed May 24 03:16:04 PDT 2017


Last month I uploaded a patch to support the
allow-popups-to-escape-sandbox flag for iframe's sandbox attribute [1].
As suggested by its name, it allows popups to escape sandboxing. I tried
to cc' people or find a reviewer on irc, but was not really successful
so far :-( Can anyone please take a look?

It seems that a bug with security involvement was fixed last year:
Basically popus were never sandboxed [2]. I see that the
allow-popups-to-escape-sandbox flag changes that behavior when it is
explicitly requested by the page's author, so I guess some careful
review (from Apple?) might be required here.

Thank you,


[1] https://bugs.webkit.org/show_bug.cgi?id=158875
[2] https://trac.webkit.org/changeset/204266

Frédéric Wang

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.webkit.org/pipermail/webkit-dev/attachments/20170524/f8645f88/attachment.bin>

More information about the webkit-dev mailing list