[prev in list] [next in list] [prev in thread] [next in thread] 

List:       webkit-unassigned
Subject:    [Webkit-unassigned] [Bug 170075] Can not read blobs in sandboxed iframes
From:       bugzilla-daemon () webkit ! org
Date:       2019-06-29 0:29:15
Message-ID: bug-170075-2851-RbIy1vIDro () https ! bugs ! webkit ! org/
[Download RAW message or body]

--1561768157.3A303c7.16540
Date: Fri, 28 Jun 2019 17:29:17 -0700
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: https://bugs.webkit.org/
Auto-Submitted: auto-generated

https://bugs.webkit.org/show_bug.cgi?id=170075

Kallyn Gowdy <kallyn.gowdy@yeticgi.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |kallyn.gowdy@yeticgi.com

--- Comment #5 from Kallyn Gowdy <kallyn.gowdy@yeticgi.com> ---
This is also an issue in Mobile Safari on iOS 12.3.1.

A workaround is to add the allow-same-origin option to the sandbox attribute, but as \
stated in the spec (http://w3c.github.io/html/semantics-embedded-content.html#element-attrdef-iframe-sandbox), \
this defeats the purpose of using the sandbox attribute.

-- 
You are receiving this mail because:
You are the assignee for the bug.
--1561768157.3A303c7.16540
Date: Fri, 28 Jun 2019 17:29:17 -0700
MIME-Version: 1.0
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: https://bugs.webkit.org/
Auto-Submitted: auto-generated

<html>
    <head>
      <base href="https://bugs.webkit.org/">
    </head>
    <body><span class="vcard"><a class="email" \
href="mailto:kallyn.gowdy&#64;yeticgi.com" title="Kallyn Gowdy \
&lt;kallyn.gowdy&#64;yeticgi.com&gt;"> <span class="fn">Kallyn Gowdy</span></a> \
</span> changed  <a class="bz_bug_link 
          bz_status_NEW "
   title="NEW - Can not read blobs in sandboxed iframes"
   href="https://bugs.webkit.org/show_bug.cgi?id=170075">bug 170075</a>
          <br>
             <table border="1" cellspacing="0" cellpadding="8">
          <tr>
            <th>What</th>
            <th>Removed</th>
            <th>Added</th>
          </tr>

         <tr>
           <td style="text-align:right;">CC</td>
           <td>
               &nbsp;
           </td>
           <td>kallyn.gowdy&#64;yeticgi.com
           </td>
         </tr></table>
      <p>
        <div>
            <b><a class="bz_bug_link 
          bz_status_NEW "
   title="NEW - Can not read blobs in sandboxed iframes"
   href="https://bugs.webkit.org/show_bug.cgi?id=170075#c5">Comment # 5</a>
              on <a class="bz_bug_link 
          bz_status_NEW "
   title="NEW - Can not read blobs in sandboxed iframes"
   href="https://bugs.webkit.org/show_bug.cgi?id=170075">bug 170075</a>
              from <span class="vcard"><a class="email" \
href="mailto:kallyn.gowdy&#64;yeticgi.com" title="Kallyn Gowdy \
&lt;kallyn.gowdy&#64;yeticgi.com&gt;"> <span class="fn">Kallyn Gowdy</span></a> \
</span></b>  <pre>This is also an issue in Mobile Safari on iOS 12.3.1.

A workaround is to add the allow-same-origin option to the sandbox attribute, but as \
stated in the spec (<a \
href="http://w3c.github.io/html/semantics-embedded-content.html#element-attrdef-iframe \
-sandbox">http://w3c.github.io/html/semantics-embedded-content.html#element-attrdef-iframe-sandbox</a>), \
this defeats the purpose of using the sandbox attribute.</pre>  </div>
      </p>


      <hr>
      <span>You are receiving this mail because:</span>

      <ul>
          <li>You are the assignee for the bug.</li>
      </ul>
    </body>
</html>
--1561768157.3A303c7.16540--


[Attachment #3 (text/plain)]

_______________________________________________
webkit-unassigned mailing list
webkit-unassigned@lists.webkit.org
https://lists.webkit.org/mailman/listinfo/webkit-unassigned


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic