Re: Disallowing setting document.domain in sandboxed iframes
Bobby Holley <[email protected]> Fri, 9 Aug 2013 09:50:35 -0700
| Newsgroups | gmane.comp.mozilla.devel.dom |
|---|---|
| Message-ID | <CAKBxTc+bPtJJCc5fj1hJU4UyUGYXLc1yqMThKp5x6N3pZXJsEA@mail.gmail.com> |
Oh, right. Yeah, that sounds fine - should make it easier to sandbox the windows, since there's no transitive closure to worry about. bholley On Fri, Aug 9, 2013 at 9:39 AM, Boris Zbarsky <[email protected]> wrote: > On 8/9/13 12:32 PM, Bobby Holley wrote: >> >> Don't sandboxed scopes already get a unique principal, for which >> document.domain is meaningless? > > > Not if you allow-same-origin. > > > -Boris > _______________________________________________ > dev-tech-dom mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-tech-dom