Skip to content

fix(playground): carry live sample allow attribute - #1977

Draft
caugner wants to merge 5 commits into
mainfrom
playground-allow
Draft

caugner wants to merge 5 commits into
mainfrom
playground-allow

Conversation

@caugner

@caugner caugner commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Description

Update live sample Playground links to carry iframe allow attributes.

Motivation

Ensure permissions policies required by live samples also apply when users open those samples in Playground.

Additional details

The allow param is only honored when the Playground was opened from a same-origin page (the breakout link uses rel="opener"), so arbitrary links cannot pair untrusted code with a first-party permission prompt. It is kept in the session and reset by Clear, like srcPrefix. Shared Playground permalinks continue to save only editor code.

Related issues and pull requests

Related to mdn/rari#349.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

b55a6f0 was deployed to: https://fred-pr1977.review.mdn.allizom.net/

An empty `allow` attribute yields the same empty container policy as
no attribute, so treating `""` as absent keeps the `allow` param out of
breakout URLs without changing behavior.
Treat `allow` like `srcPrefix`: store it in the session so a reload
after `_createPermalink` rewrites the URL keeps the permission, and
drop it in `clear()` so a cleared Playground does not retain it.
Any link could otherwise pair attacker code with `allow=camera` and
trigger a first-party permission prompt. The breakout link opens the
Playground with `rel="opener"`, so the existing origin check identifies
samples launched from MDN and drops `allow` for everything else.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant