这是indexloc提供的服务,不要输入任何密码
Skip to content

Conversation

@blu25
Copy link
Collaborator

@blu25 blu25 commented May 25, 2022

This PR introduces a monkey patch that modifies the CORP internal check to not short circuit allow for same-origin URLs if the request's destination is a fenced frame. This will ensure that fenced frames always act like cross-origin frames, regardless of the origin of its src attribute.

@blu25 blu25 requested a review from domfarolino May 25, 2022 19:01
Copy link
Collaborator

@domfarolino domfarolino left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more change, otherwise it looks good.

@domfarolino domfarolino merged commit 7e08cdf into master Jun 4, 2022
@domfarolino domfarolino deleted the liam-corp-coep branch June 4, 2022 00:44
blu25 added a commit that referenced this pull request Jun 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants