Make Theia WebViews more secure #15616
Labels
area/editor/theia
Issues related to the che-theia IDE of Che
kind/enhancement
A feature request - must adhere to the feature request template.
severity/P1
Has a major impact to usage or development of the system.
At the moment, Theia WebViews are on the same origin as Theia editor. That's not secure as WebViews have access to the Theia page and some plugin can break Theia.
Theia WebViews should have a separate origin to be isolated from Theia page.
The text was updated successfully, but these errors were encountered: