[whatwg] @srcdoc and default @sandbox
ojan at chromium.org
Mon Aug 30 14:38:55 PDT 2010
> >>> On Aug 30, 2010, at 10:02 AM, Tab Atkins Jr. wrote:
> >>>> This would mean that there is no way for an author to use @srcdoc
> >>>> *without* sandboxing. This appears to be a minority use-case in the
> >>>> first place (as far as I can tell, it's pretty much just useful for
> >>>> testing purposes), but the author can always use a data: url in that
> >>>> case.
I'm not convinced this is that small of a use-case even if it's not the
primary one. We should provide a way to turn off sandboxing if we're going
to make it the default for anything.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the whatwg