The postMessage Sanitizer: A Recipe for Anyone Building iframe Tools
When I security-audited NitroIDE for the v25 release, the worst hole I found wasn't in the iframe sandbox. It was in the trust my own parent page placed in its own iframe.
NitroIDE is a browser IDE wh
nitroide.hashnode.dev4 min read