The customer drops a Resi-hosted player page into an iframe. The most common embed, and the one the sign-in flow is designed around.
| Player runs on | control.jefflowery.dev — third-party to this page |
|---|---|
| Config comes from | query params on the frame src, mapped to data-* by standAlone() |
| Sign-in transport | iframe, escalating to a popup when storage is unreachable |
| This page can read the viewer id | no — the result is addressed to the player’s origin |
<iframe src="https://control.jefflowery.dev/webplayer/video?identifyViewer=required&id=…&type=event" class="resi-video-frame" allow="autoplay; fullscreen" allowfullscreen="true" title="Resi player"></iframe>
video.html carries data-resi-body, so isInOwnFrame() is true — but window.self !== window.top, so it is not standalone.Every postMessage delivered to this window, newest last, with repeats collapsed. In this case:
page.min.js here, so nobody sends PING_PLAYER and the player has nothing to answer — the parent contract is opt-in. See the page script case for what it looks like when it runs.[this page] if you tick the box. Not ours.
Messages tagged [this page] come from this document’s own origin and are hidden by default.
They are browser extensions: password managers, React DevTools and the like all inject content scripts that
post on this page’s behalf. Nothing from the player or the sign-in page can appear under that tag.