4 ms·
It would still break sites like codepen.io that use iframes for this.
by ceronman 5y ago
It would still break sites like codepen.io that use iframes for this.
- gregoriol 5y agocodepen's iframes are their own, not cross-origin
- mcintyre1994 5y agoThey're on another domain they own, but they are on another domain (cdpn.io) and the cross-origin concern does apply. They do that because they have auth cookies on codepen.io and don't want them exposed to the iframe. See these tweets by their cofounder: https://twitter.com/chriscoyier/status/1422940724295786503?s=20 https://twitter.com/chriscoyier/status/1422940724295786503?s... and https://twitter.com/chriscoyier/status/1420033471376920578?s=20 https://twitter.com/chriscoyier/status/1420033471376920578?s...
- asddubs 5y agoif they were on the same domain you could load iframes with the parent site and do arbitrary CSRF