Re: Disallowing setting document.domain in sandboxed iframes

Bobby Holley <[email protected]> Fri, 9 Aug 2013 09:32:30 -0700
Newsgroups gmane.comp.mozilla.devel.dom
Message-ID <CAKBxTcL8hDRB16PO=gSCY1WhkFAyBRb55T+qei=C1aTD5d5-5g@mail.gmail.com>
Don't sandboxed scopes already get a unique principal, for which
document.domain is meaningless?

Either way I am totally, 100% on board with disallowing
document.domain whenever we can.

bholley

On Thu, Aug 8, 2013 at 9:38 PM, Boris Zbarsky <[email protected]> wrote:
> Would we be willing to disallow setting document.domain in sandboxed
> iframes?  Seems like there should no content depending on that so far, and
> it would mean that sandboxed iframes could have better task/process/whatever
> isolation from the parent...
>
> Hixie is looking for some sort of implementor commitment, but I figured I
> should check here before saying anything on the whatwg list.
>
> -Boris
> _______________________________________________
> dev-tech-dom mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-tech-dom