UI Security
Brad Hill
Should we prohibit displaying content with an input-protection policy in a seamless iframe? Because CSS gets cascaded into such a frame, it arguably already has no UI integrity from it's parent - but seamless also already requires that the parent be same-origin.

Should an input-protection policy be treated as "frame-options 'deny'" when a resource is embedded with the seamless flag?

Or should we allow it, because the embedder must be same-origin? If yes, should we cascade input-protection from the embedding parent (including selectors) or attempt to continue to enforce it as-specified?
After discussion on list, no special treatment required. Spec already allows same-origin content to interfere with protected regions.

Brad Hill, 25 Nov 2013, 22:34:51

