Skip to content

Conversation

@bban160
Copy link
Contributor

@bban160 bban160 commented Dec 26, 2025

Description

Correct the stated redefinitions of allowfullscreen and allowpaymentrequest as per the relevant specs.

Motivation

The existing text states that allowfullscreen is redefined as allow="fullscreen" (shorthand for allow="fullscreen 'src'") and allowpaymentrequest is redefined as allow="payment" (shorthand for allow="payment 'src'"). In reality, both have allowlists of *, which makes a difference if the iframe is navigated away from the origin defined in its src attribute.

Additional details

allowfullscreen:

allowpaymentrequest:

@bban160 bban160 requested a review from a team as a code owner December 26, 2025 17:59
@bban160 bban160 requested review from chrisdavidmills and removed request for a team December 26, 2025 17:59
@github-actions github-actions bot added Content:HTML Hypertext Markup Language docs size/xs [PR only] 0-5 LoC changed labels Dec 26, 2025
@github-actions
Copy link
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content:HTML Hypertext Markup Language docs size/xs [PR only] 0-5 LoC changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant