Sandbox toot embeds in the embed modal

It should not be necessary thanks to our Content Security Policy, but best
be sure in case a server's CSP is incorrect. Also, avoids a CSP warning about
loading remote scripts.
main
Thibaut Girka 6 years ago committed by ThibG
parent 30de4e4dfc
commit 36d27e2891

@ -74,6 +74,7 @@ export default class EmbedModal extends ImmutablePureComponent {
className='embed-modal__iframe' className='embed-modal__iframe'
frameBorder='0' frameBorder='0'
ref={this.setIframeRef} ref={this.setIframeRef}
sandbox='allow-same-origin'
title='preview' title='preview'
/> />
</div> </div>

Loading…
Cancel
Save