mirror of
https://github.com/ArchiveBox/ArchiveBox.git
synced 2026-04-25 09:06:02 +03:00
[GH-ISSUE #800] Feature Request: Option to disable preview (iframe) to original URL #2015
Labels
No labels
expected: maybe someday
expected: next release
expected: release after next
expected: unlikely unless contributed
good first ticket
help wanted
pull-request
scope: all users
scope: windows users
size: easy
size: hard
size: medium
size: medium
status: backlog
status: blocked
status: done
status: idea-phase
status: needs followup
status: wip
status: wontfix
touches: API/CLI/Spec
touches: configuration
touches: data/schema/architecture
touches: dependencies/packaging
touches: docs
touches: js
touches: views/replayers/html/css
why: correctness
why: functionality
why: performance
why: security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/ArchiveBox#2015
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Inndy on GitHub (Jul 19, 2021).
Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/800
Type
What is the problem that your feature request solves
Use iframe to preview original URL may leak
RefererURL, cause JavaScript to be executed on browser and cookie leaved.This may cause some problem related to security and privacy.
Describe the ideal specific solution you'd want, and whether it fits into any broader scope of changes
Have an option to disable iframe preview to orignal URL, and/or option to remove
allow-scriptsfromiframe.sandboxattributeWhat hacks or alternative solutions have you tried to solve the problem?
Remove
iframetag completely from HTML template.Also, I've sent a PR (#799) to resolve the
RefererproblemHow badly do you want this new feature?