diff --git a/include/bbcode.php b/include/bbcode.php
index 6f6e43568..96242fdac 100644
--- a/include/bbcode.php
+++ b/include/bbcode.php
@@ -230,11 +230,10 @@ function bb_location($match) {
function bbiframe($match) {
$a = get_app();
- // use sandbox mode to prevent malicious goings on rather than host restriction
- // if(strpos($match[1],get_app()->get_hostname()))
- // return '' . $match[1] . '';
- return '';
+ $sandbox = ((strpos($match[1],get_app()->get_hostname())) ? ' sandbox="allow-scripts" ' : '');
+
+ return '';
}
function bb_ShareAttributesSimple($match) {
diff --git a/include/oembed.php b/include/oembed.php
index 691ef48fd..42a9881ed 100755
--- a/include/oembed.php
+++ b/include/oembed.php
@@ -164,8 +164,11 @@ function oembed_iframe($src,$width,$height) {
$a = get_app();
+ $sandbox = ((strpos($src,get_app()->get_hostname())) ? ' sandbox="allow-scripts" ' : '');
+
$s = $a->get_baseurl()."/oembed/".base64url_encode($src);
- return '';
+
+ return '';
}