Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Test TT is not enforced when taking an element out of a TT realm to a… #46432

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ziransun
Copy link
Member

… non-TT realm.

See discussions at w3c/trusted-types#425 (comment).

Copy link
Member

@lukewarlow lukewarlow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This won't work as required. You need to have the element inside the iframe (and have TT enforced in the iframe not the parent document) and then move it to the parent. CSP inherits down into the iframe as currently written so this will fail

@ziransun ziransun force-pushed the non-TT branch 2 times, most recently from 37409ee to 27e7b24 Compare May 24, 2024 14:06
@ziransun
Copy link
Member Author

This won't work as required. You need to have the element inside the iframe (and have TT enforced in the iframe not the parent document) and then move it to the parent. CSP inherits down into the iframe as currently written so this will fail

Updated. PTAL. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants