Empresas
Empregos
  • Sobre nós
  • Soluções
    • Publicação de vagas
      Publique sua vaga e receba candidatos qualificados em 48h.
    • Avaliações de candidatos
      Mais de 500 testes técnicos e psicológicos, mais anti-fraude.
    • Headhunting
      Busca executiva personalizada do início ao fim.
    • Folha de Pagamento + EOR
      Dispersão de folha e EOR em mais de 15 países da LATAM.
  • Preços
  • Empregos

0

151
Visualizações
Set headers on sandbox with srcdoc?

I'm trying to set some CSP policies on my sandboxed iframe with allow scripts. Naturally meta tags wouldn't do the trick if the iframe itself has scripts enabled and can just remove the meta tags right? Is there a way to create the iframe with srcdoc and still set the CSP or do I have to load it from a server?

about 4 years ago · Juan Pablo Isaza
1 Respostas
Responde à pergunta

0

The csp attribute does apply to srcdoc iframes. Being a local scheme, no response headers are needed. Just writing <iframe csp="defaul-src 'none'" srcdoc="something"> will enforce that CSP on the iframe and I guess do more or less what you would like. This is specified here.

Keep in mind that the csp attribute is currently only implemented in chromium. Also notice that the behaviour for srcdoc was just fixed in M90. Prior to that, I believe chromium was incorrectly discarding the csp attribute for srcdoc iframes.

about 4 years ago · Juan Pablo Isaza Relatório
Responde à pergunta
Encontrar trabalhos remotos

Descubra a nova forma de encontrar um emprego!

melhores empregos
Principais categorias de trabalho
Empresas
Postar vaga Preços Comercial
Jurídico
Termos e Condições Política de privacidade
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomende algumas ofertas para mim
Preciso de ajuda