An iframe which has both allow-scripts and allow-same-origin for its sandbox attribute can remove its sandboxing.
Content Security Policy: Ignoring 'unsafe-inline' within script-src: strict-dynamic specified
Content Security Policy: Ignoring https: within script-src: strict-dynamic specified
Content Security Policy: Ignoring http: within script-src: strict-dynamic specified
Content Security Policy: Ignoring 'unsafe-inline' within script-src: strict-dynamic specified
Content Security Policy: Ignoring https: within script-src: strict-dynamic specified
Content Security Policy: Ignoring http: within script-src: strict-dynamic specified
Content Security Policy: Ignoring 'unsafe-inline' within script-src: strict-dynamic specified
Content Security Policy: Ignoring https: within script-src: strict-dynamic specified
Content Security Policy: Ignoring http: within script-src: strict-dynamic specified
Content Security Policy: Ignoring 'unsafe-inline' within script-src: strict-dynamic specified
Content Security Policy: Ignoring https: within script-src: strict-dynamic specified
Content Security Policy: Ignoring http: within script-src: strict-dynamic specified
Content Security Policy: Ignoring 'unsafe-inline' within script-src: strict-dynamic specified
Content Security Policy: Ignoring https: within script-src: strict-dynamic specified
Content Security Policy: Ignoring http: within script-src: strict-dynamic specified
An iframe which has both allow-scripts and allow-same-origin for its sandbox attribute can remove its sandboxing.
Content Security Policy: Ignoring 'unsafe-inline' within script-src: strict-dynamic specified
Content Security Policy: Ignoring https: within script-src: strict-dynamic specified
Content Security Policy: Ignoring http: within script-src: strict-dynamic specified