Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check html is an iframe if not wrap it #28

Open
djowett opened this issue Aug 6, 2015 · 1 comment
Open

Check html is an iframe if not wrap it #28

djowett opened this issue Aug 6, 2015 · 1 comment

Comments

@djowett
Copy link
Contributor

djowett commented Aug 6, 2015

Just noting this security consideration from the oembed spec before I forget...

"When a consumer displays HTML (as with video embeds), there's a vector for XSS attacks from the provider. To avoid this, it is recommended that consumers display the HTML in an iframe, hosted from another domain. This ensures that the HTML cannot access cookies from the consumer domain."

(unless this is handled in your dependencies?)

@hvelarde
Copy link
Member

hvelarde commented Aug 6, 2015

good point, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants