2 ms·
> For the same reason that we don't call out to JS to require HTTPS but rather use HSTS, XFO is right way to block CJ. I think this is the best point in your a
by bluetooth 14y ago
> For the same reason that we don't call out to JS to require HTTPS but rather use HSTS, XFO is right way to block CJ.
I think this is the best point in your argument. If you're going to half-assedly block framing (via JS, not using XFO), you will have problems. Either through sandboxed frames, or using XSSAuditor against it, it will break.
Besides this minor issue, there really is no other serious flaw with sandbox framing.
- homakov 14y agoalright, let's blame developers! :) and regards flaws - sandbox could be more tightly coupled with Content security policy. Not a big deal, but posts look really misleading telling "put it in sandbox, well done"