Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7661183
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 31, 20262026-05-31T13:33:51+00:00 2026-05-31T13:33:51+00:00

As you may know, Pagedown is a pretty nice and simple editor, but I

  • 0

As you may know, Pagedown is a pretty nice and simple editor, but I want to extend its functionality. So far I have succeeded in doing so regarding to embedding videos, so after adding a video, you can see it in the preview window. Obviously, I had to include an iframe to allow such behavior, however, I’m a bit concerned about it security-wise.

Can you tell me what kind of dangers are lurking behind this use of iframe?. Obviously, the only purpose is to allow users to see the way his/her post would look like, so this is client-side only, but you never know when using frames.

For instance, would it be ok if I allow videos only from some domains (YouTube) or even that exposes a security vulnerability?

By the way, Google Chrome gives me this cute warning:

Unsafe JavaScript attempt to access frame with URL
file:///somethinglocaladdress from
frame with URL http://www.someaddress.com. Domains,
protocols and ports must match.

Is this something (the Google Chrome warning) I should be concerned?.

UPDATE: Notice my comment to phpgeek. It seems I’m covering his suggestions, but I’d like to get more answers to be sure I’m doing this right.

Thanks!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-31T13:33:52+00:00Added an answer on May 31, 2026 at 1:33 pm

    I don’t think this is something you need to be too concerned about.

    Regarding security- Google actually did a pretty good job at explaining it here: http://blog.chromium.org/2008/12/security-in-depth-local-web-pages.html

    Google also does outline how most other browser handle the iframe security there (at least for the older versions).

    Other than that, if your question mainly relates to security vulnerabilities relating to your server, I don’t think that this poses an issue.

    You may also be interested in checking this page out: http://code.google.com/p/browsersec/wiki/Part2#Origin_inheritance_rules

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

As you may know, when we have this code in Javascript : function getName()
As you may know, the wall rect will not update since its a copy
As you may know, MOSS 2007 offers functionality to synchronize Active Directory properties to
As many of you may know, when you have a while loop (or any
If you have used indeed.com before, you may know that for the keywords you
As you may know Coherence provides filtering api against its cache-cluster, like this: //
Many of you may know the classic windows screen saver . Does anyone have
As you may know, Silverlight does not have the TileBrush found in WPF. Is
As you may know, properties are usually written in files in key=value format but
So as you may know, if you have a text field and you add

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.