Skip to content

fix: add default iframe referrerpolicy - #15384

Open
PicardParis wants to merge 2 commits into
ipython:mainfrom
PicardParis:fix_iframe_referrerpolicy
Open

PicardParis wants to merge 2 commits into
ipython:mainfrom
PicardParis:fix_iframe_referrerpolicy

Conversation

@PicardParis

@PicardParis PicardParis commented Sep 7, 2026 •

Copy link
Copy Markdown

This is the default policy for major browsers.

Adding referrerpolicy="strict-origin-when-cross-origin" directly inside the <iframe> tag enforces this behavior at the element level, ensuring that embedded content adheres to the strict privacy policy even if a parent page or environment still uses a less secure or undefined policy.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant