Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

postMessage的安全问题 #1364

Closed
QiAnXinCodeSafe opened this issue Sep 17, 2019 · 1 comment · Fixed by #1366
Closed

postMessage的安全问题 #1364

QiAnXinCodeSafe opened this issue Sep 17, 2019 · 1 comment · Fixed by #1366

Comments

@QiAnXinCodeSafe
Copy link

你好:
该文件有两处使用postMessage的安全问题,当您使用postMessage将数据发送到其他窗口时,始终要指定精确的目标origin,而不是*。恶意网站可以拦截postMessage发送的信息。

@wssgcg1213
Copy link
Collaborator

Thanks for warning, it's not used anymore, we'll remove these files.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants