Re: Disallowing setting document.domain in sandboxed iframes

Bobby Holley <[email protected]> Fri, 9 Aug 2013 09:50:35 -0700
Newsgroups gmane.comp.mozilla.devel.dom
Message-ID <CAKBxTc+bPtJJCc5fj1hJU4UyUGYXLc1yqMThKp5x6N3pZXJsEA@mail.gmail.com>
Oh, right. Yeah, that sounds fine - should make it easier to sandbox
the windows, since there's no transitive closure to worry about.

bholley

On Fri, Aug 9, 2013 at 9:39 AM, Boris Zbarsky <[email protected]> wrote:
> On 8/9/13 12:32 PM, Bobby Holley wrote:
>>
>> Don't sandboxed scopes already get a unique principal, for which
>> document.domain is meaningless?
>
>
> Not if you allow-same-origin.
>
>
> -Boris
> _______________________________________________
> dev-tech-dom mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-tech-dom