Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 1090505
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 16, 20262026-05-16T23:22:57+00:00 2026-05-16T23:22:57+00:00

I want to allow the logged in users to view any 3rd party content

  • 0

I want to allow the logged in users to view any 3rd party content via an IFrame.

Something like allowing Gmail users to view any Web Calendar they want inside an IFrame.

Is allowing the users to set the IFrame Src Url a security problem?

What security issues will I face?

Any other need to know Tips for using IFrames will be welcome.

Thanks

Rafael

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-16T23:22:58+00:00Added an answer on May 16, 2026 at 11:22 pm

    are you afraid of users that want to harm you? then the answer is, you can’t do anything about it. they can control the source in their browser anway as they want. you have to do your security server side.

    but if you want to protect your clients from mailicous code that is on 3rd party websites that get loaded via the iframe the answer is:
    iframe is quite safe. xss/same-source-origin policies are pretty good theese days.

    well of course such a thing is always a risk.
    you don’t have to be afraid of the content in the iframe.
    what i would rather recommend is to validate the content or the src tag.
    make it a valid url and then you should be fine.

    the only thing that the page in the iframe could probably do is to redirect your page to a bad site. (as the document.location attribute is manipualteable and readable in an iframe from a different origin). there are ways to prevent that but they are not reliable.

    you could load the source of the extermal website to your server and output it setting a base href attribute to the external site, so everything will load properly, then you have the ability to check/manipulate the document. but thats pretty complicated if you want to maintain advanced stuff like javascript etc.

    to sum it up: the site cant really harm you. but the user. but if the user specifies a bad site, well its really her/his problem….

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I want to allow admins to be logged in for longer than normal users.
I have a directory and I want to allow users which are only logged
I want to allow users of my application to add sub-users and set privileges
I'm new to Python & Django. I want to allow users to create new
I'm building an app where I want to allow users to be able to
I have a form in which I allow logged in users to change their
Typically, in sites that allow membership, you want to offer your users a bit
I want to allow users to use only one system to login. if they
I want to allow my page users to embed my own video player (Flash)
I want to allow some users to access a team project portal, so I

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.