2 ms·
https://developer.mozilla.org/en-US/docs/Web/HTML/Element#embedded_content https://developer.mozilla.org/en-US/docs/Web/HTML/Element#em... <object> or <portal>
by fswd 5y ago
https://developer.mozilla.org/en-US/docs/Web/HTML/Element#embedded_content https://developer.mozilla.org/en-US/docs/Web/HTML/Element#em...
<object> or <portal> already exist. maybe they would work?
- lol768 5y ago<portal> is an experiment/pet project pushed (and only implemented!) by one browser vendor, which as far as I know remains feature flagged. It was shipped behind a flag with an initial implementation vulnerable to a same origin policy bypass as well as local file disclosure. As far as I can tell the only reason it wasn't assigned a Moz standards position of "harmful" is because Google argued "it's actually still a work in progress!" (three years ago). Refs: - https://research.securitum.com/security-analysis-of-portal-element/ https://research.securitum.com/security-analysis-of-portal-e... - https://github.com/mozilla/standards-positions/issues/157 https://github.com/mozilla/standards-positions/issues/157