[
https://issues.apache.org/jira/browse/CB-10324?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15094592#comment-15094592
]
Nikhil Khandelwal commented on CB-10324:
----------------------------------------
There is no plan to derive the whitelist from CSP headers currently.
> iframe created in JavaScript does not load
> ------------------------------------------
>
> Key: CB-10324
> URL: https://issues.apache.org/jira/browse/CB-10324
> Project: Apache Cordova
> Issue Type: Bug
> Components: iOS
> Affects Versions: 4.0.1
> Reporter: Gregor Schmidt
>
> When dynamically creating an {{iframe}}, the {{iframe}}'s {{src}} is never
> loaded. This worked without issues using 3.9.2.
> Example Code:
> {code:javascript}
> i = document.createElement("iframe");
> i.src = "https://example.org";
> document.body.appendChild(i);
> {code}
> Please note, that you have to extend the {{Content-Security-Policy}} headers
> to include {{https:}} to pass CSP restrictions.
> I have also created a sample project to reproduce the problem. You may find
> it at https://github.com/schmidt/cordova-ios-iframe-example
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]