Loading
Add <iframe> provider model and parser
What does this MR do and why?
Adds the <iframe> provider model and parser to the codebase, with no callers.
The provider model has been developed in conjuction with AppSec; see #599713 and https://gitlab.com/gitlab-com/gl-security/product-security/appsec/appsec-reviews/-/work_items/326 (staff-only), in particular https://gitlab.com/gitlab-com/gl-security/product-security/appsec/appsec-reviews/-/work_items/326#note_3306306968.
MR stack
MR 1/9 of Rework <iframe> embed configuration (#599713):
- Add `<iframe>` provider model and parser (!254943 - merged)
⬅️ you are here - Add `<iframe>` provider loader and base config (!254944 - merged)
- Convert `<iframe>` allowlist setting to provide... (!254945)
- Draft: Move to `<iframe>` providers (!254946)
- Draft: Remove dead `<iframe>` transform code (!254947)
- Draft: Frontend `<iframe>` hardening (!254948)
- Draft: Click-to-activate functionality for `<if... (!254949)
- Draft: Admin UI for `<iframe>` providers (!254950)
- Draft: Mark `<iframe>` provider loader and conf... (!255246)
Part of <iframe> embeds in Markdown content (#282443).
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Asherah Connor