You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@cordova.apache.org by "Steve Gill (JIRA)" <ji...@apache.org> on 2016/09/29 23:54:21 UTC

[jira] [Assigned] (CB-10324) Derive whitelist tags from CSP

     [ https://issues.apache.org/jira/browse/CB-10324?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Steve Gill reassigned CB-10324:
-------------------------------

    Assignee: Steve Gill

> Derive whitelist tags from CSP
> ------------------------------
>
>                 Key: CB-10324
>                 URL: https://issues.apache.org/jira/browse/CB-10324
>             Project: Apache Cordova
>          Issue Type: Improvement
>          Components: Android, iOS
>    Affects Versions: 4.0.1
>            Reporter: Gregor Schmidt
>            Assignee: Steve Gill
>            Priority: Minor
>
> When dynamically creating an {{iframe}}, the {{iframe}}'s {{src}} is never loaded. This worked without issues using 3.9.2.
> Example Code:
> {code:javascript}
> i = document.createElement("iframe");
> i.src = "https://example.org";
> document.body.appendChild(i);
> {code}
> Please note, that you have to extend the {{Content-Security-Policy}} headers to include {{https:}} to pass CSP restrictions.
> I have also created a sample project to reproduce the problem. You may find it at https://github.com/schmidt/cordova-ios-iframe-example



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscribe@cordova.apache.org
For additional commands, e-mail: issues-help@cordova.apache.org