Weasyl / weasyl

The website.
https://www.weasyl.com
Apache License 2.0
115 stars 30 forks source link

Flash test case for security-related settings #1391

Open charmander opened 6 months ago

charmander commented 6 months ago

allowScriptAccess and allowNetworking(/credentialAllowList) are security-critical Ruffle settings; we should have a convenient Flash test case to ensure that they’re working. And maybe even put Ruffle in a sandboxed iframe, because its sparse security-related documentation is kind of worrying. Thankfully, it’s click-to-load.