zeroclipboard / zeroclipboard.github.io

The ZeroClipboard demo website.
http://zeroclipboard.github.io/
10 stars 16 forks source link

IFrame security analysis pages #17

Closed JamesMGreene closed 9 years ago

JamesMGreene commented 9 years ago

Created test pages to analyze iframe sandboxing and its impact on ZeroClipboard (a sandboxed iframe is not allowed to instantiate plugins).

This is why ZeroClipboard no longer works on JSFiddle, CodePen, etc. However, the analysis results illuminated at least one interesting possibility: both of those sites have their sandboxes setup such that they could be removed by the child frame and readded afterward (if readding it doesn't destroy plugin instances, that is). So, we can at least show those who want to use ZeroClipboard on JSFiddle/CodePen how to game the system and explain to them why it is necessary (boo, Flash Player).

Ref zeroclipboard/zeroclipboard#511

http://zeroclipboard.org/test-iframes.html (or locally, http://localhost:3000/test-iframes-local.html)

JamesMGreene commented 9 years ago

P.S. @jonrohan: This PR snuck Bootstrap into the site... but only on the iframe test pages :wink: