maildev@lists.thunderbird.net

Thunderbird email developers

View all threads

An iframe which has both allow-top-navigation and allow-top-navigation-by-user-activation for its sandbox attribute will permit top navigations

I
ISHIKAWA,chiaki
Sun, Jun 7, 2020 6:44 AM

I filed bugzilla:
 Bug 1643986 C-C mochitest warning. - An iframe which has both
allow-top-navigation and allow-top-navigation-by-user-activation for its
sandbox attribute will permit top navigations

Between last weekend and this weekend, something has changed, and I got
a lot of warning regarding "An iframe which ..." in my local mochitest.

Someone in the know ought to check whether the particular warning can be
safely ignored or something needs to be done.

The warning seems to suggest there is a security implication.

Strange thing is that I don't see the warning in try-C-C. Maybe the
particular warning has landed very lately. Maybe Saturday night (Japan
Standard Time)?
https://searchfox.org/mozilla-central/source/dom/locales/en-US/chrome/security/security.properties#51
(It seems so. The patch was dated June 1.)

TIA

I filed bugzilla:  Bug 1643986 C-C mochitest warning. - An iframe which has both allow-top-navigation and allow-top-navigation-by-user-activation for its sandbox attribute will permit top navigations Between last weekend and this weekend, something has changed, and I got a lot of warning regarding "An iframe which ..." in my local mochitest. Someone in the know ought to check whether the particular warning can be safely ignored or something needs to be done. The warning seems to suggest there is a security implication. Strange thing is that I don't see the warning in try-C-C. Maybe the particular warning has landed very lately. Maybe Saturday night (Japan Standard Time)? https://searchfox.org/mozilla-central/source/dom/locales/en-US/chrome/security/security.properties#51 (It seems so. The patch was dated June 1.) TIA