ember-cli / ember-cli/ember-twiddle

Should the iframe point to a different domain?

Open
#99 16 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
268
Forks
87
PR merge metrics
No merged PRs in 30d

Description

Firstly, the app is really cool. Hats off!!

In order to prevent XSS attacks and other security issues, should the iframe in ember-twiddle point to a different domain? Similar to JSFiddle. Currently, we can access the parent window from the iframe code and can access the browser cookies as well.

Correct me if my understanding is wrong.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.