Andrew Grieve created CB-2179: --------------------------------- Summary: Warn developers about including third-party content in their apps. Key: CB-2179 URL: https://issues.apache.org/jira/browse/CB-2179 Project: Apache Cordova Issue Type: Bug Components: Docs Reporter: Andrew Grieve Assignee: Andrew Grieve Priority: Minor Fix For: 2.4.0
We expose our native APIs to iframes as well as top-level content, so we should warn against using iframes for third-party code. Might make sense to change "Domain Whitelist Guide" -> "Security & Whitelist Guide" and then add a section to it about the dangers of embedding untrusted content. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira