JavaScript Restrict or prevent iframe navigation

I have a top page which contains an iframe with untrusted content. I am hosting the untrusted content on a domain that I control, and can (in theory) make changes to it. Short of analyzing the source code with something like Google Caja, is there any way that I can prevent the untrusted content from navigating the frame itself to other URLs? (or ideally restrict it to the trusted domain)

Related, but not quite:

  • Only addresses anchor tags, not navigation in general
  • Lots and lots of webpages talking about sandbox with "allow-top-navigation". Doesn't help because I want to restrict navigation of the frame itself

Background: My goal is to allow untrusted content to run in the iframe and to pass some user data to it, but I don't want the untrusted content to turn around and send this data to a 3rd-party. (The content will be allowed instead to postMessage any results to an API exposed by the parent window.) Content Security Policy HTTP headers on the untrusted content allow me to restrict all manner of network requests except navigation.

Answer:1

new guy here. I have a feeling this is an extremely basic question but I can't get this Jquery code to write the output of the function to html and have it show up. I believe it's an issue with the ...

new guy here. I have a feeling this is an extremely basic question but I can't get this Jquery code to write the output of the function to html and have it show up. I believe it's an issue with the ...

  1. canvas
  2. canada
  3. cancelled
  4. canceled vs cancelled
  5. cancun
  6. canada goose
  7. cane corso
  8. canes
  9. canadian prime minister
  10. cancun flights
  11. canker sore
  12. candy
  13. cancer
  14. canon
  15. canvas prints
  16. cancer sign
  17. candace owens
  18. canada news
  19. candytopia
  20. canlis

I have a report with checkboxes in each row and one submit button. I want to disable button when all checkboxes are unchecked. Button should be only enabled when at least one checkbox is checked on ...

I have a report with checkboxes in each row and one submit button. I want to disable button when all checkboxes are unchecked. Button should be only enabled when at least one checkbox is checked on ...

  1. disabled enabled button jquery
  2. disabled enabled button javascript
  3. disabled enabled button css
  4. enable disable button
  5. enable disabled button html

I have a minified app.min.js file which is ~ 80Kb big and contains all javascript code my website requires. If I include this file as script with source pointing to app.min.js everything works fine, ...

I have a minified app.min.js file which is ~ 80Kb big and contains all javascript code my website requires. If I include this file as script with source pointing to app.min.js everything works fine, ...

  1. jade minify javascript

In my script I am loading an image from an array into a div, then I calculate some style elements to be tuned. The problem is that this works only if I use a timeout function before calculating the ...

In my script I am loading an image from an array into a div, then I calculate some style elements to be tuned. The problem is that this works only if I use a timeout function before calculating the ...