Iframe embed

The customer drops a Resi-hosted player page into an iframe. The most common embed, and the one the sign-in flow is designed around.

Player runs on control.jefflowery.dev — third-party to this page
Config comes from query params on the frame src, mapped to data-* by standAlone()
Sign-in transport iframe, escalating to a popup when storage is unreachable
This page can read the viewer id no — the result is addressed to the player’s origin

The markup

<iframe
  src="https://control.jefflowery.dev/webplayer/video?identifyViewer=required&id=…&type=event"
  class="resi-video-frame"
  allow="autoplay; fullscreen"
  allowfullscreen="true"
  title="Resi player"></iframe>

Expected

Messages reaching this page

Every postMessage delivered to this window, newest last, with repeats collapsed. In this case:

cross-origin 0 this page 0 carrying a viewer id 0

Messages tagged [this page] come from this document’s own origin and are hidden by default. They are browser extensions: password managers, React DevTools and the like all inject content scripts that post on this page’s behalf. Nothing from the player or the sign-in page can appear under that tag.