A frame with no sandbox, a script from anywhere
- Forbidden
<iframe src="https://third-party">with nosandbox; a<script src>pointing at an origin nobody chose, on a page that takes payments or credentials- Instead
sandboxwith only the capabilities the embed needs, andallownarrowed the same way. Third-party script on a sensitive page is a decision, recorded with a reason (DECISIONS.md), not a default.
What this rule looks like
Why this rule
An embedded frame runs somebody else's code inside your page, and a script tag hands them the same origin your session lives in. Both are sometimes right; neither is ever automatic.
- Kind
- Rule
- Section
- Things to avoid
- Group
- Safety at the interface
- Bucket
- mechanical
- Severity
- warning
- Detector
interface-safety- Since
- v0.14.0