X
點擊此處開啟此網站的行動版。

技術支援討論區

false security warning on login forms within an iframe

已張貼

I have a login form which uses an iframe to insulate the password from the rest of the app.

All content both in the parent window and the iframe is loaded over https, however I'm still getting the "This content is not secure..." message.

Why is this?

The iframe is loaded with `sandbox="allow-forms allow-scripts"` eg. without Same-Origin (This is to prevent code running in the parent window introspecting the login form to find passwords).

Could this be the cause of the problem? If so, is it intentional, could it be documented or fixed?

I have a login form which uses an iframe to insulate the password from the rest of the app. All content both in the parent window and the iframe is loaded over https, however I'm still getting the "This content is not secure..." message. Why is this? The iframe is loaded with `sandbox="allow-forms allow-scripts"` eg. without Same-Origin (This is to prevent code running in the parent window introspecting the login form to find passwords). Could this be the cause of the problem? If so, is it intentional, could it be documented or fixed?
引用

額外的系統細節

已安裝的外掛程式

none

應用程式

  • User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.80 Safari/537.36

更多資訊

提出問題者

For some reason my attached screenshot didn't come through the first time, see attached.

URL is https://events.handsupfoundation.org/login/

For some reason my attached screenshot didn't come through the first time, see attached. URL is https://events.handsupfoundation.org/login/
這篇文章有幫助嗎?
引用
問個問題

如果您還沒有帳號,您必須先 登入您的帳號 來回覆文章。請 開始一個新問題