5 ms·
I see that some of the email clients mentioned wrap the mail’s content in extra HTML tags and modify the CSS and classes names. I’m wondering why email clients
by maaaaattttt 3y ago
I see that some of the email clients mentioned wrap the mail’s content in extra HTML tags and modify the CSS and classes names. I’m wondering why email clients don’t use sandboxed iframes to render HTML email? Do they still present security risks?
- red_trumpet 3y agoThe extra HTML does not happen from the client reading the forwarded email, but when forwarding. That is expected, because the forwarding party might want to add more text to the email.
- echoangle 3y agoAt least the person forwarding the mail could check the preview and see that the text changed.
- Savageman 3y agoIn the past I had issues using iframes. Not for rendering or security issue (those work great in my memory). But if your email has a link to your website, and your sandbox iframe disallow Javascript, then this "security context" is carried over to the page that was opened from clicking the link inside the iframe, and you website cannot use JS. [edit] The solution was "allow-popups-to-escape-sandbox", so I see no reason it would not work.