The in-app browser runs inside a sandboxed iframe, isolating external websites from your school data and SmartSchool OS session.
Every page you visit in the browser loads inside an iframe with strict sandbox attributes. This means the external website:
Session isolation
External sites cannot access your SmartSchool JWT or auth cookies.
No pop-ups
The sandbox blocks pop-up windows and forced redirects.
CSP enforced
Content Security Policy headers prevent script injection.
HTTPS preferred
The browser warns when navigating to non-HTTPS sites.
Some websites block being loaded inside iframes (via X-Frame-Options headers). When this happens, the browser shows a message explaining that the site cannot be displayed inline. You can still copy the URL and open it in a separate browser tab.
💡 Tip
Most educational resources and search engines work well inside the sandbox. Social media sites and banking sites commonly block iframe embedding.