Preventing mouse clicks with Office.js

The documentation at https://github.com/OfficeDev/office-js-docs/blob/master/docs/develop/privacy-and-security.md#tips-to-prevent-clickjacking lists several ways to prevent clicks, by User confirmation before performing potentially dangerous actions.

I was wondering if it would not be safe to display any user interface on the page until it was called Office.initialize? Or is there a way for an iframe attacker to add my add-on on their page and somehow replace the Office SDK with a malicious version?

0
source share
1 answer

, . , , . , , .

0

Source: https://habr.com/ru/post/1692414/


All Articles