Re: [w3c/payment-request] Disable Payment Request API in CSP/iframe sandbox (#698)

This is interesting... usually we do not add features to both allow*/feature policy and iframe sandboxing. But, the fact that for top-level pages payment request is on by default, whereas in iframes it is off by default, makes this complicated.

Paging @clelland, our feature policy expert, for this thoughts.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/payment-request/issues/698#issuecomment-378006311

Received on Monday, 2 April 2018 18:41:41 UTC