Iframe embed, sandboxed correctly

The same hardening with the flags sign-in actually needs. This is the recipe to hand a customer who insists on a sandbox.

Player runs on control.jefflowery.dev — third-party to this page
Sandbox allow-scripts allow-same-origin allow-popups allow-popups-to-escape-sandbox
Sign-in transport iframe, escalating to a popup when storage is unreachable
This page can read the viewer id no

The markup

<iframe
  src="https://control.jefflowery.dev/webplayer/video?identifyViewer=required&id=…&type=event"
  class="resi-video-frame"
  sandbox="allow-scripts allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  allow="autoplay; fullscreen"
  title="Resi player"></iframe>

Expected

Messages reaching this page

Every postMessage delivered to this window, newest last, with repeats collapsed. In this case:

cross-origin 0 this page 0 carrying a viewer id 0

Messages tagged [this page] come from this document’s own origin and are hidden by default. They are browser extensions: password managers, React DevTools and the like all inject content scripts that post on this page’s behalf. Nothing from the player or the sign-in page can appear under that tag.