Add attribute allow-top-navigation-by-user-activation to iframe sandbox
Categories
(Core :: DOM: Core & HTML, enhancement, P2)
Tracking
()
Tracking | Status | |
---|---|---|
firefox79 | --- | fixed |
People
(Reporter: binlu, Assigned: jkt)
References
Details
(Keywords: dev-doc-complete)
Attachments
(1 file)
![]() |
||
Comment 2•8 years ago
|
||
![]() |
||
Updated•8 years ago
|
Updated•8 years ago
|
Updated•8 years ago
|
![]() |
||
Comment 4•7 years ago
|
||
Comment 6•7 years ago
|
||
Updated•7 years ago
|
Comment 10•7 years ago
|
||
Comment 11•7 years ago
|
||
![]() |
||
Comment 12•7 years ago
|
||
Reporter | ||
Comment 13•7 years ago
|
||
![]() |
||
Comment 14•7 years ago
|
||
Comment 15•7 years ago
|
||
![]() |
||
Comment 16•7 years ago
|
||
Comment 17•7 years ago
|
||
Comment 18•7 years ago
|
||
Comment 19•7 years ago
|
||
![]() |
||
Comment 20•7 years ago
|
||
Updated•7 years ago
|
Comment 21•6 years ago
|
||
Comment 22•6 years ago
|
||
See https://www.admonsters.com/can-sandboxing-defeat-redirects/ for motivation. "While Chrome (versions 58 and later) has enabled the control, Firefox, Safari, and Internet Explorer prior to 10 have not."
Reporter | ||
Comment 23•6 years ago
|
||
(In reply to Brian Smith (:briansmith, :bsmith, use NEEDINFO?) from comment #22)
See https://www.admonsters.com/can-sandboxing-defeat-redirects/ for motivation. "While Chrome (versions 58 and later) has enabled the control, Firefox, Safari, and Internet Explorer prior to 10 have not."
Just a clarification: Safari has supported this on both Mac & iOS since April 2018: https://bugs.webkit.org/show_bug.cgi?id=171327, which is also mentioned above.
So with Edge moving to use Chromium, Firefox would be the only major browser not supporting this.
Comment 24•6 years ago
|
||
FWIW, here's an example of where another major open source project could take advantage of this if it existed, which would improve UX for millions of users:
Assignee | ||
Comment 25•5 years ago
|
||
Updated•5 years ago
|
Comment 26•5 years ago
|
||
Comment 30•5 years ago
|
||
bugherder |
Comment 31•5 years ago
|
||
Docs work completed; see https://github.com/mdn/sprints/issues/3414#issuecomment-652566772 for the full details.
The MDN iframe page already describes the new token nicely, so there was not much to do here.
Updated•4 years ago
|
Description
•