Conversation
Contributor
|
b55a6f0 was deployed to: https://fred-pr1977.review.mdn.allizom.net/ |
An empty `allow` attribute yields the same empty container policy as no attribute, so treating `""` as absent keeps the `allow` param out of breakout URLs without changing behavior.
Treat `allow` like `srcPrefix`: store it in the session so a reload after `_createPermalink` rewrites the URL keeps the permission, and drop it in `clear()` so a cleared Playground does not retain it.
Any link could otherwise pair attacker code with `allow=camera` and trigger a first-party permission prompt. The breakout link opens the Playground with `rel="opener"`, so the existing origin check identifies samples launched from MDN and drops `allow` for everything else.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Update live sample Playground links to carry iframe
allowattributes.Motivation
Ensure permissions policies required by live samples also apply when users open those samples in Playground.
Additional details
The
allowparam is only honored when the Playground was opened from a same-origin page (the breakout link usesrel="opener"), so arbitrary links cannot pair untrusted code with a first-party permission prompt. It is kept in the session and reset by Clear, likesrcPrefix. Shared Playground permalinks continue to save only editor code.Related issues and pull requests
Related to mdn/rari#349.