Skip to content

Allow "self" frame ancestors to fix customizer#20

Merged
allysonsouza merged 1 commit intomainfrom
allow-self-frame-embed
Jan 9, 2025
Merged

Allow "self" frame ancestors to fix customizer#20
allysonsouza merged 1 commit intomainfrom
allow-self-frame-embed

Conversation

@kadamwhite
Copy link
Collaborator

The WordPress customizer uses an iframe to embed the site, so we need to permit "self" ancestors on the CSP frame directive.

WIKI-1052

The WordPress customizer uses an iframe to embed the site, so we need to permit "self" ancestors on the CSP frame directive.

WIKI-1052

Signed-off-by: K Adam White <kadamwhite@users.noreply.github.com>
@kadamwhite
Copy link
Collaborator Author

This has been merged to develop for testing, but should also be good to roll directly to main. Deferring until sprint starts unless Allyson finds its necessary to fix WIKI-1050

@allysonsouza
Copy link
Collaborator

I've tested it locally and it does fix the problem.

@allysonsouza allysonsouza merged commit 89aa419 into main Jan 9, 2025
1 check passed
@allysonsouza allysonsouza deleted the allow-self-frame-embed branch January 9, 2025 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants