Skip to content

Restrict CodeFrame postMessage origin - #1606

Open
avinxshKD wants to merge 1 commit into
processing:v1from
avinxshKD:fix/codeembed-postmessage-origin
Open

avinxshKD wants to merge 1 commit into
processing:v1from
avinxshKD:fix/codeembed-postmessage-origin

Conversation

@avinxshKD

@avinxshKD avinxshKD commented Sep 24, 2026 •

Copy link
Copy Markdown

Fixes #1605

Summary

  • send the p5.js source message only to the page origin
  • validate the message origin inside the iframe
  • accept the message only when it comes from the parent window
  • require the parent origin when generating iframe markup

Testing

  • npx vitest run test/components/CodeFrame.test.tsx --project DOM --reporter=verbose
  • npx eslint src/components/CodeEmbed/frame.tsx test/components/CodeFrame.test.tsx
  • npm run check

@avinxshKD

Copy link
Copy Markdown
Author

@doradocodes hey this is PR #2 of what you asked under #!350, PTAL.

@avinxshKD
avinxshKD force-pushed the fix/codeembed-postmessage-origin branch from 9cfb3d2 to 729b7fa Compare September 25, 2026 09:45
@Nwakaego-Ego

Copy link
Copy Markdown
Contributor

Hi @avinxshKD, thank you for working on this PR. I tested it locally, and the embedded sketches continued to load, reset, and run correctly.

I also confirmed that postMessage now uses window.location.origin instead of the wildcard "*", and that the iframe checks both event.origin and event.source. All three CodeFrame tests passed.

cc @doradocodes

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants