Skip to content

docs(browser-keys): note sandboxed-iframe (Origin: null) limitation#27

Merged
mikedotexe merged 1 commit into
mainfrom
browser-keys-docs
Jun 24, 2026
Merged

docs(browser-keys): note sandboxed-iframe (Origin: null) limitation#27
mikedotexe merged 1 commit into
mainfrom
browser-keys-docs

Conversation

@mikedotexe

Copy link
Copy Markdown
Collaborator

A sandboxed <iframe> sends Origin: null and usually omits Referer, so a website-restricted key 403s even on the operator's own domain. Add a failure-mode entry (EN + ru) so operators don't expect an embedded widget to work with a restricted browser key. Addresses the PR #20 review design note.

A sandboxed <iframe> sends Origin: null and usually omits Referer, so a
website-restricted key 403s even on the operator's own domain. Add a
failure-mode entry (EN + ru) so operators don't expect an embedded widget to
work with a restricted browser key. Addresses the PR #20 review design note.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying builder-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 10aa369
Status: ✅  Deploy successful!
Preview URL: https://25af3a73.builder-docs.pages.dev
Branch Preview URL: https://browser-keys-docs.builder-docs.pages.dev

View logs

@mikedotexe
mikedotexe merged commit 7305357 into main Jun 24, 2026
2 checks passed
@mikedotexe
mikedotexe deleted the browser-keys-docs branch June 24, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant