[wp-trac] [WordPress Trac] #44400: Adjust `sandbox` attribute for Sutori embeds via oEmbed discovery

WordPress Trac noreply at wordpress.org
Tue Jun 19 16:02:49 UTC 2018


#44400: Adjust `sandbox` attribute for Sutori embeds via oEmbed discovery
--------------------------------------+------------------------------
 Reporter:  yoran                     |       Owner:  (none)
     Type:  feature request           |      Status:  new
 Priority:  normal                    |   Milestone:  Awaiting Review
Component:  Embeds                    |     Version:
 Severity:  normal                    |  Resolution:
 Keywords:  dev-feedback 2nd-opinion  |     Focuses:
--------------------------------------+------------------------------

Comment (by swissspidy):

 > Are there any services that have exceptions like 2, i.e. whitelist or
 extend certain attributes on the iframe? If so, I was hoping we could add
 Sutori as such an exception.

 No, there aren't any such exceptions in core right now. Adding `allow-
 same-origin` for your site only would set quite a precedent. Adding it for
 every site just because of this is also dangerous without carefully
 verifying at the consequences.

 Sort of related: #44281.

 Suggesting ''wontfix''.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/44400#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list