oEmbed Iframes
-
In the oembed spec, (see oembed.com) it suggests that returned media should be placed inside an iframe to avoid XSS attacks. However, I have noticed in using this feature that wordpress doesn’t perform this function automatically.
Instead, there is the concept of an oEmbed ‘whitelist’, which is a list of supported oEmbed providers.
So I guess my question is, why did wordpress go down the whitelist route, rather than simply allow any embed provider, and check that the content returned was iframed to avoid the security issue?
thanks,
Rob
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘oEmbed Iframes’ is closed to new replies.