[wp-trac] [WordPress Trac] #35894: Post embeds are useless with X-Frame-Options: SAMEORIGIN

WordPress Trac noreply at wordpress.org
Sun Feb 21 11:11:31 UTC 2016


#35894: Post embeds are useless with X-Frame-Options: SAMEORIGIN
-------------------------------------+------------------
 Reporter:  ethitter                 |       Owner:
     Type:  defect (bug)             |      Status:  new
 Priority:  normal                   |   Milestone:  4.5
Component:  Embeds                   |     Version:  4.4
 Severity:  normal                   |  Resolution:
 Keywords:  has-patch needs-testing  |     Focuses:
-------------------------------------+------------------
Changes (by swissspidy):

 * keywords:   => has-patch needs-testing
 * milestone:  Awaiting Review => 4.5


Comment:

 That does indeed sound like a bug to me.

 Right now we're actually revealing the iframe when we successfully
 retrieve a message from it. It just has no effect because this was already
 done by some leftover code in the `onLoad()` function of the embed script.

 [attachment:35894.diff] should fix this.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/35894#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list