Skip to content

Scope "Allow Cross-Origin iframes" to origins matching the entry's URLs, instead of blanket-allowing all cross-origin iframes #3097

Description

@pacewicz

Feature request.

Filling into a legitimate cross-origin auth iframe (e.g. www.icloud.com embedding the Apple ID sign-in form from idmsa.apple.com) currently requires enabling Allow Cross-Origin iframes in Site Preferences for the top page. That flag whitelists every cross-origin iframe on that site for credential retrieval — the help text rightly warns "Use at your own risk." Related: #2937, #2903.

Proposal: add an option (per-site, or a global default) that permits cross-origin iframe filling only when the iframe's origin matches a URL already configured on the matching entry (main URL or Additional URLs), instead of blanket-allowing all cross-origin iframes on the site.

In the iCloud example the user already has https://idmsa.apple.com on the entry, so the extension already knows the exact allowed origin — no blanket toggle needed. This reuses the existing iframe URL/TLD matching (#2166, #2265); the only behavioral change is gating the fill on that match rather than a site-wide switch.

Why it's safer: a compromised or injected third-party iframe on an allowed site cannot receive credentials unless its origin is one the user explicitly added to the entry. It turns an all-or-nothing site flag into a least-privilege, per-origin allow that the user already maintains as part of normal entry hygiene.

Suggested UX: a Site Preferences mode / radio — "Allow all cross-origin iframes" (current behavior) vs "Allow only iframe origins listed on the matching entry" (new; could reasonably be the default).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions