Sign in

Craig Francis

@craigfrancis.bsky.social
52 followers 79 following 67 posts

Security, Accessibility, Performance... trying to make the world better… live in Bristol, UK.

PostsRepliesMedia
Reposted by Craig Francis
Eiji Kitamura / えーじ @agektmr.com · 29/09/2026
Connection Allowlists announcement blog post has been published. developer.chrome.com/blog/connect...
developer.chrome.com
Connection allowlists: Secure your web application's network access  |  Blog  |  Chrome for Developers
Chrome 152 introduces connection allowlists, a new security mechanism that lets you create a strict network sandbox for your documents and workers.
0175
Reposted by Craig Francis
Eiji Kitamura / えーじ @agektmr.com · 25/09/2026
"Responsive iframes" are now available in Chrome 154, letting an iframe size itself to fit the content of the document it embeds.
242
Reposted by Craig Francis
Nilesh Prajapati @nileshprajapati.com · 23/09/2026
New in Chrome 154: iframes that automatically resize themselves to their content by @bram.us #html
bram.us
New in Chrome 154: iframes that automatically resize themselves to their content
Chrome 154 adds support for responsively-sized iframes, letting an <iframe> size itself based on the intrinsic size of its embedded document. This is perfect for seamlessly embedding third-party comme...
5547
Reposted by Craig Francis
Web Standards @web-standards.dev · 22/09/2026
Responsive iframes in Chrome 154. Sebastian Benz and Bramus introduce frame-sizing, a CSS property that sizes an <iframe> to its content, with a <meta> element opt-in and window.requestResize() for later updates. #html #css developer.chrome.com...
Chrome logo, an illustration of a scrollable embedded page, an HTML snippet with a responsive-embedded-sizing <meta> element, a frame-sizing CSS snippet, and title “Responsive iframes in Chrome 154”.
3328
Reposted by Craig Francis
Eiji Kitamura / えーじ @agektmr.com · 16/09/2026
"Connection Allowlists," a browser-level security mechanism that blocks any outbound network communication not matching your permitted URL patterns, is now available starting in Chrome 152.
111
Craig Francis @craigfrancis.bsky.social · 28/08/2026
@jakearchibald.com As you know everything about CSS (weird stuff, and in development)… is there a way for a (blocking) style sheet to apply rules (e.g. display none) only until DOMContentLoaded; so a <script defer> can avoid FOUC, fail safe (if it fails to load), and work with a no-inline CSP?
100
Craig Francis @craigfrancis.bsky.social · 14/08/2026
Who thought it would be a good idea to use the Emergency Alert to say people in the UK shouldn’t have a BBQ?
000
Reposted by Craig Francis
IntentToShip @intenttoship.dev · 14/05/2026
Blink: Intent to Ship: Responsively-sized <iframe>
groups.google.com
Blink: Intent to Ship: Responsively-sized <iframe>
Blink: Intent to Ship: Responsively-sized <iframe>
1339
Craig Francis @craigfrancis.bsky.social · 25/04/2026
@sarasoueidan.com hi, wondered if you have thoughts on CSS “prefers-reduced-motion: reduce”… I’ve got a checkbox, when ticked it shows more content, should I continue to animate height (show it appearing, within 0.5 seconds) or simply change from display none to block (might be disorientating?)
100
Reposted by Craig Francis
Firefox for Web Developers @webdevs.firefox.com · 24/02/2026
The Sanitizer API landed in Firefox 148, along with element.setHTML(). This lets you fully configure how HTML strings are cleaned as they're parsed. hacks.mozilla.org/2026/02/good...
hacks.mozilla.org
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
Cross-site scripting (XSS) remains one of the most prevalent vulnerabilities on the web. The new standardized Sanitizer API provides a straightforward way for web developers to sanitize untrusted…
120357
Craig Francis @craigfrancis.bsky.social · 11/02/2026
Petition: “By-elections to be called automatically when MPs defect to another party” Response: “no plans to change […] voters elect individual candidates, and not the political party they represent” If true, then remove the party from the ballot paper!
010
Reposted by Craig Francis
Freddy @freddyb.bsky.social · 07/12/2025
New blog post: Why the Sanitizer API is just `setHTML()` - frederikbraun.de/why-sethtml.html
04117
Reposted by Craig Francis
Dominique Righetto @righettod.eu · 29/11/2025
📡 OWASP Secure Headers Project: Over the years, we have compiled a collection of HTTP response headers that disclose technical information. We are continuing our research to find new ones on our own, but we have decided to ask our community for help in finding new ones. #appsec #owasp_shp
121
Craig Francis @craigfrancis.bsky.social · 18/09/2025
Why do I keep seeing the words “Cable Street”? Seems to be random, maybe I’m noticing it because it’s in one of my favorite books (Night Watch, by Terry Pratchett). en.wikipedia.org/wiki/Battle_...
000
Craig Francis @craigfrancis.bsky.social · 08/09/2025
Could we put all the racists on their own island, so they can make their own country to be “proud” of?
000
Reposted by Craig Francis
phpukconference.bsky.social @phpukconference.bsky.social · 22/01/2025
Are you safe from injection vulnerabilities? Even using abstraction layers like Doctrine or parameterised queries mistakes can still happen. @craigfrancis.bsky.social shows us how mistakes can be made and what can be done to mitigate them. Buy your ticket here: buff.ly/40Ck2WR #phpuk
011
Reposted by Craig Francis
Lukas Weichselbaum @webappsec.dev · 16/11/2024
XSS vulnerabilities keeping you up at night? 😱 Google's new "Commitment to Secure by Design" whitepaper has answers! Safe Coding and web platform improvements are key. Read more (page 7): static.googleusercontent.com/media/public...
static.googleusercontent.com
082
Craig Francis @craigfrancis.bsky.social · 29/11/2023
SQL Injection still exists despite abstractions like ORMs, QueryBuilders, & Parameterised Queries; simply because it’s easy to make mistakes (especially for new developers). Programming languages could find/stop these mistakes by identifying “trusted developer defined strings”: eiv.dev
eiv.dev
Ending Injection Vulnerabilities
How programming languages and libraries can being an end to Injection Vulnerabilities.
020