-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Snow can be bypassed with inline script #141
Comments
At this point he should just disable iframe srcdoc. nobody actually uses it |
We have, just not sufficiently. See latest PR |
Thanks for contributing. The main maintainer of this project is temporary unavailable, but we'll definitely get back to this. Meanwhile we're also working with W3C to propose a basic building block of Snow getting introduced into the browser so that all of the monkey-patching can be eliminated in the future. https://www.w3.org/2023/03/secure-the-web-forward/talks/realms.html Feel free to update this issue with comments on how you think it should be addressed. We may reach out with questions later. |
@deryilz The motivation behind Snow originally was to not limit anything the web offers, unless they are extra niece.
Some of them, to my surprise, use It has been afterwards decided to lose this attitude in favor of security (see https://weizmangal.com/2023/08/03/snow-stops-playing-nice/), |
The text was updated successfully, but these errors were encountered: