1

Suppose www.youtube.com have no X-Frame-Options set.

Imagine I'm already logged in to YouTube. Now from another web page in the same browser I'm loading YouTube in an iframe, will the browser send all the auth-cookies to the YouTube loaded in the iframe so that it will be loaded as logged in?

Anders
  • 64,406
  • 24
  • 178
  • 215
3lokh
  • 181
  • 5

1 Answers1

1

By default, yes, though the sandbox parameter in the iframe tag can change this behavior.

David
  • 15,814
  • 3
  • 48
  • 73