3 ms·
I believe a caveat with this technique is that it won't work for sites that send the X-Frame-Options header as SAMEORIGIN in supporting browsers.
by rossta 11y ago
I believe a caveat with this technique is that it won't work for sites that send the X-Frame-Options header as SAMEORIGIN in supporting browsers.
- tomhallett 11y agoAgreed. Another caveat: this technique won't work if the website has iframe busting javascript code. The iframe will reset the source of the top level page and will cripple your app. If you control the domains you are embedding this won't be a problem, but if you don't - then it's a risk to be aware of.
- leonkenneth 11y agoIf your target browsers support it, you can use the `sandbox` attribute and avoid supplying the `allow-top-navigation` flag to prevent this behaviour. Granted, this won't prevent other framebusting techniques such as checking the parent before rendering.