mirror of
https://github.com/zulip/zulip.git
synced 2025-10-23 04:52:12 +00:00
While there are legitimate use cases for embedded Zulip in an iFrame, they're rare, and it's more important to prevent this category of attack by default. Sysadmins can switch this to a whitelist when they want to use frames.