mirror of
https://github.com/LadybirdBrowser/ladybird.git
synced 2025-06-17 07:41:54 +00:00
LibWeb: Disallow cross-origin access to <iframe>.contentDocument
With this patch, we now enforce basic same-origin policy for this one <iframe> attribute. To make it easier to add more attributes like this, I've added an extended IDL attribute ("[ReturnNullIfCrossOrigin]") that does exactly what it sounds like. :^)
This commit is contained in:
parent
4c1f317572
commit
37c287b1d4
Notes:
sideshowbarker
2024-07-19 02:16:20 +09:00
Author: https://github.com/awesomekling
Commit: 37c287b1d4
4 changed files with 28 additions and 4 deletions
|
@ -7,6 +7,5 @@ interface HTMLIFrameElement : HTMLElement {
|
|||
[Reflect] attribute DOMString width;
|
||||
[Reflect] attribute DOMString height;
|
||||
|
||||
readonly attribute Document? contentDocument;
|
||||
|
||||
[ReturnNullIfCrossOrigin] readonly attribute Document? contentDocument;
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue