SitePoint Sponsor

User Tag List

Results 1 to 4 of 4
  1. #1
    SitePoint Addict svcghost's Avatar
    Join Date
    Oct 2010
    Posts
    288
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    iFrames and Same Origin Policy

    Hey guys,

    It's been bugging me a lot lately that I cannot grab the current href location URL of an iframe on a site, with different domains. I understand how SOP is great and secure, but it's still a pain for those who are not trying to cause harm. What is the maximum harm of allowing just the ability to read the current location URL of an iFrame? I am not talking src attribute.

    Is there a site that I can see every single thing excluded in iFrames due to Same Origin Policy? as well as things that are permitted?

  2. #2
    Unobtrusively zen silver trophybronze trophy
    paul_wilkins's Avatar
    Join Date
    Jan 2007
    Location
    Christchurch, New Zealand
    Posts
    14,702
    Mentioned
    101 Post(s)
    Tagged
    4 Thread(s)
    Quote Originally Posted by svcghost View Post
    Is there a site that I can see every single thing excluded in iFrames due to Same Origin Policy? as well as things that are permitted?
    You can see what is appowed at this iframe doicumentation page, which also links through to the Same origin policy for JavaScript documentation page.
    Programming Group Advisor
    Reference: JavaScript, Quirksmode Validate: HTML Validation, JSLint
    Car is to Carpet as Java is to JavaScript

  3. #3
    SitePoint Addict svcghost's Avatar
    Join Date
    Oct 2010
    Posts
    288
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    So basically there is no way to ever get the URL of an external site in an iFrame, UNLESS you collaborate with the developer of that external site? (like the postMessage workaround)?

  4. #4
    Unobtrusively zen silver trophybronze trophy
    paul_wilkins's Avatar
    Join Date
    Jan 2007
    Location
    Christchurch, New Zealand
    Posts
    14,702
    Mentioned
    101 Post(s)
    Tagged
    4 Thread(s)
    Quote Originally Posted by svcghost View Post
    So basically there is no way to ever get the URL of an external site in an iFrame, UNLESS you collaborate with the developer of that external site?
    I prefer to think of it as cooperation.
    Programming Group Advisor
    Reference: JavaScript, Quirksmode Validate: HTML Validation, JSLint
    Car is to Carpet as Java is to JavaScript


Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •