vue/no-unsandboxed-iframe
Require a sandbox attribute on iframe elements
Default severity: warning
Presets: happy-path, nuxt, ecosystem, opinionated
Automatic fix: None; review the suggested change
Applies to: Vue SFC templates and blocks, with script context where the rule requires it
Options: No rule-specific options. Severity and preset selection are configurable.
Configuration (Vite+)
import { defineConfig } from "@vizejs/vite-plugin/vite-plus";
export default defineConfig({
lint: {
vize: {
"preset": "incremental",
"rules": {
"vue/no-unsandboxed-iframe": "warn"
}
},
},
});
vp run lint
Bad
The embedded frame has no sandbox attribute limiting its capabilities.
<template>
<iframe src="/embed"></iframe>
</template>
Good
sandbox applies restrictions; allow-scripts explicitly opts into that one capability when needed.
<template>
<iframe src="/embed" sandbox></iframe>
<iframe src="/embed" sandbox="allow-scripts"></iframe>
</template>
Good avoids this rule's finding under the configuration above; other rules may still report diagnostics.