Feature request.
Filling into a legitimate cross-origin auth iframe (e.g. www.icloud.com embedding the Apple ID sign-in form from idmsa.apple.com) currently requires enabling Allow Cross-Origin iframes in Site Preferences for the top page. That flag whitelists every cross-origin iframe on that site for credential retrieval — the help text rightly warns "Use at your own risk." Related: #2937, #2903.
Proposal: add an option (per-site, or a global default) that permits cross-origin iframe filling only when the iframe's origin matches a URL already configured on the matching entry (main URL or Additional URLs), instead of blanket-allowing all cross-origin iframes on the site.
In the iCloud example the user already has https://idmsa.apple.com on the entry, so the extension already knows the exact allowed origin — no blanket toggle needed. This reuses the existing iframe URL/TLD matching (#2166, #2265); the only behavioral change is gating the fill on that match rather than a site-wide switch.
Why it's safer: a compromised or injected third-party iframe on an allowed site cannot receive credentials unless its origin is one the user explicitly added to the entry. It turns an all-or-nothing site flag into a least-privilege, per-origin allow that the user already maintains as part of normal entry hygiene.
Suggested UX: a Site Preferences mode / radio — "Allow all cross-origin iframes" (current behavior) vs "Allow only iframe origins listed on the matching entry" (new; could reasonably be the default).
Feature request.
Filling into a legitimate cross-origin auth iframe (e.g.
www.icloud.comembedding the Apple ID sign-in form fromidmsa.apple.com) currently requires enabling Allow Cross-Origin iframes in Site Preferences for the top page. That flag whitelists every cross-origin iframe on that site for credential retrieval — the help text rightly warns "Use at your own risk." Related: #2937, #2903.Proposal: add an option (per-site, or a global default) that permits cross-origin iframe filling only when the iframe's origin matches a URL already configured on the matching entry (main URL or Additional URLs), instead of blanket-allowing all cross-origin iframes on the site.
In the iCloud example the user already has
https://idmsa.apple.comon the entry, so the extension already knows the exact allowed origin — no blanket toggle needed. This reuses the existing iframe URL/TLD matching (#2166, #2265); the only behavioral change is gating the fill on that match rather than a site-wide switch.Why it's safer: a compromised or injected third-party iframe on an allowed site cannot receive credentials unless its origin is one the user explicitly added to the entry. It turns an all-or-nothing site flag into a least-privilege, per-origin allow that the user already maintains as part of normal entry hygiene.
Suggested UX: a Site Preferences mode / radio — "Allow all cross-origin iframes" (current behavior) vs "Allow only iframe origins listed on the matching entry" (new; could reasonably be the default).