Joomla & WordPress Tutorials, Info, Discussion, Tips | GavickPro Blog

Chrome is the 1st browser to support HTML5 Sandbox

The HTML 5 is maturing slowly but sustained and often appear implemented new features. This will in all likelihood, the versions of HTML that will bring more changes to how we build Web pages. The release of new stable versions of Chrome turns it into the first browser to support a security feature of HTML, the implementation of the sandbox’s iframes.

With this new feature we are going to be able to control the execution of iframes external to our sites. We begin to be able to put iframes, but set execute permissions to external code and reduced privileges.

We thus control all the information we receive from outside sources and we do not control. It’s just nice to realize that we had a page as a reliable and we present our website now provides advertising or pop-ups that have javascript unhealthy to run on your side.

Its form is simple to implement, just that we put the statement inside the sandbox iframe tag. From this time frame that no longer has permissions to execute any code. Will only show the html, no longer able to call pop-ups or run javascript.

But if we want we can create whitelists of implementation and define possible assignments to be executed. Just as in education sandbox define it. The example below shows how to enable the implementation of javascript and forms.

Naturally, this additional safety barrier is completely ignored by older browsers that do not understand and HTML5, so this should be used to supplement the others that exist.

A simple way to test and implement the sandbox for iframe is:

If you want to see all the attributes of iframe sandbox, you can consult them here
And the other features present in HTML5 can be found on this page.

Slowly the new generation browsers start to implement the new features of HTML5, which enables those who develop Web pages, using their full potential. New times for the Internet are coming. Credits: pplware / Pedro Simões

Share