learn-awesome / learn

A social network of lifelong learners built around humanity's universal learning map.
https://learnawesome.org/
Other
343 stars 40 forks source link

By clickjacking I can edit the fields in the website #246

Open jayant766 opened 2 years ago

jayant766 commented 2 years ago

I want to fix this bug. Please let me know what I can do for fixing it.

https://user-images.githubusercontent.com/73739820/130770323-0a5fde4c-9070-4f38-99ad-aab860a4c6c4.mp4

nileshtrivedi commented 2 years ago

We allow our site to be embedded in other origins because that is the way our web extension works. You can see how we can continue to have the extension work fine for both Mozilla and Chromium-based browsers and then propose a solution.

nileshtrivedi commented 2 years ago

Hi @jayant766 , did you see my reply above and get a chance to look into how our web extension works? I'd love to figure out a solution for this so that I can disable things like iframe embedding as well as CORS for the entire learnawesome.org domain.