How to prevent CSRF/XSRF attacks involving embedded iframes?

Is there a way to restrict what an iframe is allowed to do in the parent? What I am looking for is a security model surrounding Javascript that looks something like: … <script type=”text/javascript” src=”jquery-1.3.2.min.js”></script> <script type=”text/javascript”> function AllowedToAccess() { } function NotAllowedToAccess() { } </script> <security> iframe { Deny All; Allow javascript:AllowedToAccess(); } iframe […]

Return all page iFrames without id element

I tried this the intuitive way with both JavaScript and jQuery, with no dice for either. document.GetElementsByTagName(‘iframe’); got me: Uncaught TypeError: Object # has no method ‘GetElementsByTagName’ and $(‘iframe’) got me undefined. Is an iframe an element? Is there a way to do this? I’m trying to return all the page iframes. Thank you.

How can I redirect HTML form submission to an iframe?

I’m trying to implement a workaround to the problem of using AJAX with multi-part form data. This page looks like a good idea. Bascially, instead of using AJAX you redirect the output of the form submission to an iframe. However, it isn’t quite working for me. Here’s my client-side HTML code: <form id=”submitDocumentForm” target=’upload_target’ name=”submitDocumentForm” […]

Jquery ('#iframeid').load() is executed before Iframe CONTENT (text, images) are loaded

I’m trying to access data of an Iframe’s Iframe. To force my javascript function to wait I use jqueries .load function. But still my javascript code get’s executed “sometimes” before the iframe‘s content is fully loaded. By sometimes I mean that the behavior is different for different computers. On slower computers it waits most times […]

How to set the caret position on an editable iframe?

I need to set the caret position on a contentEditable iframe. It needs to work on Google Chrome and Firefox (no need for IE). How can I do that? I’ve tried var ifr = document.querySelector(“.myIframe”); var idoc = ifr.contentDocument; var ibody = ifr.contentDocument.body; // content: “teststring|” var caret = 2; var sel = ifr.contentDocument.getSelection(); var […]

Need jQuery UI dialog “window” to scroll to the top when a form inside an iframe is submitted

I’ve probably overcomplicated things, but being relatively new to the whole process, I didn’t know what else to do. I have an order form inside an iframe, which is inside a jQuery UI dialog lightbox. It all works, except for one problem: when the form is submitted and it redirects to either the thank-you or […]

Div is covered by youtube embed, how do I fix that?

Code: http://jsfiddle.net/DerNalia/vmNP4/ The gray menu in the top right is supposed to be above the videos. Why isn’t it? How do I make it so the div is always on top of the videos, regardless of positions?

Access parent object in JavaScript from iFrame/Window

How do I access a global object or array defined in a parent window in the child window. <script> var events_data; function function_to_fill_events_data () { . . . } </script> <div> <div><iframe src=”mini.php” width:100%; height: 100%;” scrolling=”no”></iframe> </div> </div> When I am in the mini document I’d like to be able to access the events_data […]

IFrame call parent function

is it possible for an iframe to call a parent’s function, even if they are not in the same domain? My actual approach lifts a security error when they are not on the same domain: <script> function test() { alert(‘wow’); } </script> <iframe src=”….”></iframe> And inside the iframe i would do this: <script> function fin() […]

How to fit PDF file horizontally in an iframe?

I’ve been struggling to make pdf fit horizontally dynamically https://www.modelica.org/events/modelica2011/authors-guide/example-abstract.pdf#toolbar=0&navpanes=0&scrollbar=0&view=FitH But it does not work in firefox. You can see demo here though this demo works properly. http://jsfiddle.net/raanx/1/