How to implement reliable iframes after html-sanitation?

If I use google-caja html sanitizer with my default whitelist, then it will not let me embed an iframe .

I know that a security risk is why it does not allow me to do this. But there are so many trusted websites that provide functionality through an iframe , for example. google maps, twitter button, etc.

So, please suggest me how I can implement trusted so that my user can use this functionality.

+4
source share

Source: https://habr.com/ru/post/1499608/


All Articles