Skip to content

Commit d4f4ea6

Browse files
committed
chore: add safety comment for allow-same-origin sandbox flag
References issue #3 — allow-same-origin is required for import maps in srcdoc iframes but weakens the sandbox. Document the tradeoff.
1 parent 2c37a83 commit d4f4ea6

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

apps/app/src/components/generative-ui/widget-renderer.tsx

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -700,6 +700,9 @@ export function WidgetRenderer({ title, description, html }: WidgetRendererProps
700700
content streamed via postMessage for progressive rendering. */}
701701
<iframe
702702
ref={iframeRef}
703+
// allow-same-origin is required for import maps to work in srcdoc iframes.
704+
// Safe here because no auth/session data is exposed client-side.
705+
// See: https://github.com/CopilotKit/OpenGenerativeUI/issues/3
703706
sandbox="allow-scripts allow-same-origin"
704707
className="w-full border-0"
705708
onLoad={() => setLoaded(true)}

0 commit comments

Comments
 (0)