Skip to content
GitHub
Sections

Reference · Things to avoid

A frame with no sandbox, a script from anywhere

Forbidden
<iframe src="https://third-party"> with no sandbox; a <script src> pointing at an origin nobody chose, on a page that takes payments or credentials
Instead
sandbox with only the capabilities the embed needs, and allow narrowed the same way. Third-party script on a sensitive page is a decision, recorded with a reason (DECISIONS.md), not a default.

What this rule looks like

Forbidden
Instead

Why this rule

An embedded frame runs somebody else's code inside your page, and a script tag hands them the same origin your session lives in. Both are sometimes right; neither is ever automatic.

Kind
Rule
Section
Things to avoid
Group
Safety at the interface
Bucket
mechanical
Severity
warning
Detector
interface-safety
Since
v0.14.0

Read as plain text