[webkit-dev] Review of patch to support iframe's allow-popups-to-escape-sandbox?

Frédéric WANG fred.wang at free.fr
Wed May 24 03:16:04 PDT 2017


Hello,

Last month I uploaded a patch to support the
allow-popups-to-escape-sandbox flag for iframe's sandbox attribute [1].
As suggested by its name, it allows popups to escape sandboxing. I tried
to cc' people or find a reviewer on irc, but was not really successful
so far :-( Can anyone please take a look?

It seems that a bug with security involvement was fixed last year:
Basically popus were never sandboxed [2]. I see that the
allow-popups-to-escape-sandbox flag changes that behavior when it is
explicitly requested by the page's author, so I guess some careful
review (from Apple?) might be required here.

Thank you,

Frédéric

[1] https://bugs.webkit.org/show_bug.cgi?id=158875
[2] https://trac.webkit.org/changeset/204266


-- 
Frédéric Wang


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.webkit.org/pipermail/webkit-dev/attachments/20170524/f8645f88/attachment.bin>


More information about the webkit-dev mailing list