stephenmcd / filebrowser-safe

File manager for Mezzanine
Other
42 stars 104 forks source link

Mark views as allowed for same origin iframes #72

Closed dsanders11 closed 8 years ago

dsanders11 commented 8 years ago

TinyMCE on editing page content lets you browse images via an iframe in a modal, so if settings are set to deny iframes by default, the filebrowser views won't be accessible. Mark them as allowed for same origin iframe usage, should be perfectly safe since they're already protected by staff-only.