Skip to content

Check iframe sandbox flags such as (allow-same-origin) in a case-insensitive way #1269

@dvoytenko

Description

@dvoytenko

To make sure users do not try to workaround our restrictions, e.g. using "allow-Same-origin". I'd assume just lowecasing the sandbox string before checks would suffice.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions