First Test U-Tube Iframe in a Marquee Box

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

Threaded View
A U-Tube Iframe in a Marquee Box

isn't allowed because a marquee
could be inside 'white-space: pre'


By: Anonymous


[IE11] [Feature request] Support for CSS Marquee - by Internet Explorer User

Help us narrow down the issue by selecting one of the following areas:  
reporting guidelines)

What is the expected behavior?  (bug reporting guidelines)

Internet Explorer 11 supports CSS Marquee.

Steps to reproduce the problem (include URL if applicable):  (bug  

Is this issue specific to  Internet Explorer Developer Channel?

est-support-for-css-marquee# >  

U-Tube Iiframe-sandbox in a Marquee Box

Quoted text here. Click to load it

In this example,
some completely-unknown,
potentially hostile,
user-provided HTML content is embedded in a page.

Because it is served from a separate domain,
it is affected by all the normal cross-site restrictions.

In addition, the embedded page has scripting disabled,
plugins disabled,
forms disabled,
and it cannot navigate any frames or windows other than itself
(or any frames or windows it itself embeds).

<p>We're not scared of you! Here is your content, unedited:</p>

<iframe sandbox  
src=" "></if

It is important to use a separate domain
so that if the attacker convinces the user to visit that page directly,
the page doesn't run in the context of the site's origin,
which would make the user vulnerable to any attack found in the page.

Code Example:

In this example,
a gadget from another site is embedded.
The gadget has scripting and forms enabled,
and the origin sandbox restrictions are lifted,
allowing the gadget to communicate with its originating server.

The sandbox is still useful,
as it disables plugins and popups,
thus reducing the risk of the user being exposed to malware
and other annoyances.

<iframe sandbox="allow-same-origin allow-forms allow-scripts"
        src=" "></iframe>

Quoted text here. Click to load it


Site Timeline