Sandbox toot embeds in the embed modal

It should not be necessary thanks to our Content Security Policy, but best
be sure in case a server's CSP is incorrect. Also, avoids a CSP warning about
loading remote scripts.
th-downstream
Thibaut Girka 6 years ago committed by ThibG
parent d16638a116
commit e4b9a8da07

@ -74,6 +74,7 @@ export default class EmbedModal extends ImmutablePureComponent {
className='embed-modal__iframe'
frameBorder='0'
ref={this.setIframeRef}
sandbox='allow-same-origin'
title='preview'
/>
</div>

Loading…
Cancel
Save