• last updated 9 hours ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates
"An iframe which has both allow-scripts and allow-same-origin for its sandbox attribute can remove its sandboxing"

See e.g. https://cloud.google.com/blog/products/data-analytics/iframe-sandbox-tutorial

We set in xooauth/tcl/lti-procs.tcl a restrictive default (all sandboxing restrictions are applied by default). Users should relax it according to their embedded application.

xooauth/www/admin/lti-test.tcl is not really a productive file, so we set the already hardcoded value to no-sandboxing and note that this would be appropriate.

  1. … 1 more file in changeset.
remove old-style idiom

fix typo

avoid call to deprecated function, simplify code

Aolserver/Naviserver builtin ns-parsequery already embeds URL decoding

Use the new 'url' input type widget

  1. … 1 more file in changeset.
Use naviserver api to parse URL variables

  1. … 1 more file in changeset.
added LTI test page

file lti-test.adp was initially added on branch oacs-5-10.

file lti-test.tcl was initially added on branch oacs-5-10.