You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@cordova.apache.org by "Steve Gill (JIRA)" <ji...@apache.org> on 2016/09/29 23:54:21 UTC
[jira] [Assigned] (CB-10324) Derive whitelist tags from CSP
[ https://issues.apache.org/jira/browse/CB-10324?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Steve Gill reassigned CB-10324:
-------------------------------
Assignee: Steve Gill
> Derive whitelist tags from CSP
> ------------------------------
>
> Key: CB-10324
> URL: https://issues.apache.org/jira/browse/CB-10324
> Project: Apache Cordova
> Issue Type: Improvement
> Components: Android, iOS
> Affects Versions: 4.0.1
> Reporter: Gregor Schmidt
> Assignee: Steve Gill
> Priority: Minor
>
> When dynamically creating an {{iframe}}, the {{iframe}}'s {{src}} is never loaded. This worked without issues using 3.9.2.
> Example Code:
> {code:javascript}
> i = document.createElement("iframe");
> i.src = "https://example.org";
> document.body.appendChild(i);
> {code}
> Please note, that you have to extend the {{Content-Security-Policy}} headers to include {{https:}} to pass CSP restrictions.
> I have also created a sample project to reproduce the problem. You may find it at https://github.com/schmidt/cordova-ios-iframe-example
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscribe@cordova.apache.org
For additional commands, e-mail: issues-help@cordova.apache.org