The same hardening with the two flags sign-in actually needs. This is the recipe to hand a customer who insists on a sandbox.
| Player runs on | control.jefflowery.dev — third-party to this page |
|---|---|
| Sandbox | allow-scripts allow-same-origin allow-popups allow-popups-to-escape-sandbox |
| Sign-in transport | iframe, escalating to a popup when storage is unreachable |
| This page can read the viewer id | no |
<iframe src="https://control.jefflowery.dev/webplayer/video?identifyViewer=required&id=…&type=event" sandbox="allow-scripts allow-same-origin allow-popups allow-popups-to-escape-sandbox" allow="autoplay; fullscreen" title="Resi player"></iframe>
allow-popups lets the window open at all. allow-popups-to-escape-sandbox is the one people miss: without it the popup inherits the sandbox, and the provider’s login page runs crippled inside it.allow-same-origin is required too, or the frame gets an opaque origin and has no storage of its own to sign into.Same as the plain iframe case.