Skip to content
This repository was archived by the owner on Sep 6, 2025. It is now read-only.

Conversation

@e9x
Copy link

@e9x e9x commented Feb 25, 2023

This will require more thorough testing, but it appears to be effective based on my testing.

e9x added 2 commits February 18, 2023 12:51
In order to implement this, iframe baseURIs must be recognized.
location will still report about:blank, but the base URI or __uv.base will be reliable
@e9x e9x linked an issue Feb 25, 2023 that may be closed by this pull request
@e9x e9x force-pushed the 25-iframe-windows-can-easily-be-hijacked branch from 5f3fbee to 4568101 Compare February 28, 2023 03:11
@tytech039
Copy link

giphy

itschasa

This comment was marked as outdated.

@itschasa
Copy link

I found this to give issues when doing recaptcha, anyone else the same?

@e9x
Copy link
Author

e9x commented Apr 27, 2024

I found this to give issues when doing recaptcha, anyone else the same?

yea that's the main reason why I've been hesitant to merge this, captchas don't work

@e9x e9x mentioned this pull request Mar 16, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

IFrame windows can easily be hijacked.

5 participants