Iframe warning issue

14 years 6 days ago #129938 by udjamaflip
Iframe warning issue was created by udjamaflip
Hi guys,

I'm not a CB user myself as I've never had a need, however, there is a lot of people who want to use my administrator template that use CB who are unable to due to a "security feature" where iframes are not allowed and gives this error: "Iframes not allowed, could be hack attempt..., sorry!"

Is there anyway the CB dev team could take into account the host of the parent page before blocking the page from being displayed within an iframe? The link to the latest version of the admin template is below. I would like CB users to have the freedom to use the template, but apart from me patching your code (which isn't the best way to go, as it would probably break on updates) my hands are tied.

udjamaflip.com/joomla-jquery-template/56-free-joomla-admin-template.html

Any advice on the issue would be appreciated. I am trying to get this template in Joomla core build for 1.7 but without CB's cooperation this won't happen due to unusability.

Please Log in to join the conversation.

14 years 6 days ago #129941 by beat
Replied by beat on topic Re:Iframe warning issue
The javascript code for that is in admin.comprofiler.html.php lines 21-23.

If you have a secure alternative code suggestion, which works and is tested in all current browsers (FF, safari, opera, ie7 included for backend access), contributions are welcome in here :)

The reason to jump the admin area out of any iframe is that it is an added security measure against sophisticated XSS attacks.

You have a very cool template btw. Didn't think of that issue when i saw it.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

13 years 4 months ago #147806 by mrhypefm
Replied by mrhypefm on topic Re:Iframe warning issue
I can not find it in CB 1.3 :(


Where can i find it so i can use this template?

Greetze Pascal

Please Log in to join the conversation.

13 years 4 months ago #147894 by krileon
Replied by krileon on topic Re:Iframe warning issue
mrhypefm wrote:

I can not find it in CB 1.3 :(


Where can i find it so i can use this template?

Greetze Pascal

Please review the comments on the users site concerning that template. Feedback has been provided via Comments on how to resolve your issue. I don't recommend the iFrame usage for security reasons, but you're free to adjust the core as necessary.

If you've a better suggestion for a checking mechanism we'd be glad to review for implementation that is safe with internal iframes.

Post edited by: krileon, at: 2010/12/06 17:24


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.203 seconds

Facebook Twitter LinkedIn