[GH-ISSUE #800] Feature Request: Option to disable preview (iframe) to original URL #2015

Open
opened 2026-03-01 17:55:50 +03:00 by kerem · 0 comments
Owner

Originally created by @Inndy on GitHub (Jul 19, 2021).
Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/800

Type

  • General question or discussion
  • Propose a brand new feature
  • Request modification of existing behavior or design

What is the problem that your feature request solves

Use iframe to preview original URL may leak Referer URL, cause JavaScript to be executed on browser and cookie leaved.
This may cause some problem related to security and privacy.

Describe the ideal specific solution you'd want, and whether it fits into any broader scope of changes

Have an option to disable iframe preview to orignal URL, and/or option to remove allow-scripts from iframe.sandbox attribute

What hacks or alternative solutions have you tried to solve the problem?

Remove iframe tag completely from HTML template.

Also, I've sent a PR (#799) to resolve the Referer problem

How badly do you want this new feature?

  • It's an urgent deal-breaker, I can't live without it
  • It's important to add it in the near-mid term future
  • It would be nice to have eventually

  • I'm willing to contribute dev time / money to fix this issue
  • I like ArchiveBox so far / would recommend it to a friend
  • I've had a lot of difficulty getting ArchiveBox set up
Originally created by @Inndy on GitHub (Jul 19, 2021). Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/800 <!-- Please fill out the following information, feel free to delete sections if they're not applicable or if long issue templates annoy you :) --> ## Type - [ ] General question or discussion - [ ] Propose a brand new feature - [x] Request modification of existing behavior or design ## What is the problem that your feature request solves <!-- e.g. I need to be able to archive spanish and french subtitle files from a particular <example.com> movie site that's going down soon. --> Use iframe to preview original URL may leak `Referer` URL, cause JavaScript to be executed on browser and cookie leaved. This may cause some problem related to security and privacy. ## Describe the ideal specific solution you'd want, and whether it fits into any broader scope of changes <!-- e.g. I specifically need a new archive method to look for multilingual subtitle files related to pages. The bigger picture solution is the ability for custom user scripts to be run in a puppeteer context during archiving. --> Have an option to disable iframe preview to orignal URL, and/or option to remove `allow-scripts` from [`iframe.sandbox` attribute](https://developer.mozilla.org/en-US/docs/Web/HTML/Element/iframe#attr-sandbox) ## What hacks or alternative solutions have you tried to solve the problem? <!-- A clear and concise description of any alternative solutions, workarounds, or other software you've considered using to fix the problem. --> Remove `iframe` tag completely from HTML template. Also, I've sent a PR (#799) to resolve the `Referer` problem ## How badly do you want this new feature? - [ ] It's an urgent deal-breaker, I can't live without it - [x] It's important to add it in the near-mid term future - [ ] It would be nice to have eventually --- - [x] I'm willing to contribute [dev time](https://github.com/ArchiveBox/ArchiveBox#archivebox-development) / [money](https://github.com/sponsors/pirate) to fix this issue - [ ] I like ArchiveBox so far / would recommend it to a friend - [ ] I've had a lot of difficulty getting ArchiveBox set up
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/ArchiveBox#2015
No description provided.