On Thu, May 14, 2015 at 3:59 PM, Devdatta Akhawe <dev.akh...@gmail.com> wrote: > > 2. Add a `allow-unsandboxed-auxiliary` keyword to those supported by the >> `sandbox` attribute, which, when present, would allow auxiliary browsing >> contexts created by `window.open` and `target="_blank"` links to create >> clean browsing contexts, unaffected by the sandbox which spawned them. >> >> > Why isn't a child iframe of the sandboxed iframe an auxiliary browsing > context? >
Because it's a nested browsing context. Auxiliary browsing contexts are related to a context, but not through nesting: https://html.spec.whatwg.org/multipage/browsers.html#auxiliary-browsing-contexts. It's just a definitional thing. -mike -- Mike West <mk...@google.com>, @mikewest Google Germany GmbH, Dienerstrasse 12, 80331 München, Germany, Registergericht und -nummer: Hamburg, HRB 86891, Sitz der Gesellschaft: Hamburg, Geschäftsführer: Graham Law, Christine Elizabeth Flores (Sorry; I'm legally required to add this exciting detail to emails. Bleh.)