| OLD | NEW |
| (Empty) | |
| 1 <?php |
| 2 if ($_GET["suborigin"]) { |
| 3 header("Content-Security-Policy: suborigin " . $_GET["suborigin"]); |
| 4 } |
| 5 ?> |
| 6 <!DOCTYPE html> |
| 7 <html> |
| 8 <script> |
| 9 window.secret = ''; |
| 10 window.onmessage = function() { |
| 11 var iframe = document.getElementById('iframe'); |
| 12 var secret; |
| 13 try { |
| 14 secret = iframe.contentWindow.secret; |
| 15 } catch (e) { |
| 16 secret = e.toString(); |
| 17 } |
| 18 parent.postMessage(secret, '*'); |
| 19 }; |
| 20 </script> |
| 21 <?php |
| 22 if ($_GET["childsuborigin"]) { |
| 23 echo "<iframe id=\"iframe\" src=\"post-to-parent.php?suborigin=" . $_GET["ch
ildsuborigin"] . "\"></iframe>"; |
| 24 } else { |
| 25 echo "<iframe id=\"iframe\" src=\"post-to-parent.php\"></iframe>"; |
| 26 } |
| 27 ?> |
| 28 </html> |
| OLD | NEW |