Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport release_3_9] XSS: allow iframe in popups #4954

Merged
merged 1 commit into from
Nov 7, 2024

Conversation

3liz-bot
Copy link
Contributor

@3liz-bot 3liz-bot commented Nov 7, 2024

Backport #4953
Authored by: @nboisteault

Allow iframe but add `sandbox="allow-scripts allow-forms"` to avoid XSS
@github-actions github-actions bot added this to the 3.9.0 milestone Nov 7, 2024
@github-actions github-actions bot added the run end2end If the PR must run end2end tests or not label Nov 7, 2024
@Gustry Gustry added the sponsored development This development has been funded label Nov 7, 2024
@nboisteault nboisteault merged commit 6962d67 into release_3_9 Nov 7, 2024
14 checks passed
@nboisteault nboisteault deleted the backport-4953-to-release_3_9 branch November 7, 2024 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
run end2end If the PR must run end2end tests or not sponsored development This development has been funded
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants