【问题标题】:Cross-origin frame issue while accessing the iframe contentDocument property访问 iframe contentDocument 属性时出现跨域框架问题
【发布时间】:2016-04-12 17:43:04
【问题描述】:

我需要什么:我想将脚本注入到网页中呈现的所有 iframe(窗口)中(作为我的 chrome 扩展开发的一部分)。

这样做时,我正在访问 iframe 元素 contentDocument 属性,它会导致下面提到的错误。

错误:Error: Failed to read the 'contentDocument' property from 'HTMLIFrameElement': Blocked a frame with origin "xxx.com" from accessing a cross-origin frame. at Error (native) at checkLoaded (chrome-extension://hkdhfkdhfkdhfkdhfkdhfkdhkdkd/js/app.js:152:33)

我知道我们无法访问具有不同域的元素或框架。但在我的场景中并非如此。

我是如何验证的:

Protocol = https (Not able mention it as part of URLs as stackoverflow is not allowing me do so)

iframe.src = xxx.com/dfg/rty?id=50061000000pOCB&isdtp=vw&inCon…85f85811b751bf4b4a18b5e&IFrameOrigin=https%3A%2F%2Fxxx

iframe.ownerdocument.location.origin = xxx.com

从以上信息我们可以了解到 iframe 和它的父文档都具有相同的域。

然后我检查了执行脚本的文档域(chrome 扩展内容脚本页面),因为内容脚本与我获得相同域 (xxx.com) 的网页共享相同的文档,但内容-脚本网址不同(chrome-extension://kfhdkfdhfilddfldf/js/app.js)。这样做会导致问题。

任何人都可以尝试向我解释为什么会发生跨域问题,尽管 iframe 中的域是相同的。

【问题讨论】:

标签: javascript security iframe google-chrome-extension


【解决方案1】:

正如我在问题中所说,我的要求是将脚本注入每个子窗口(iframe)。

如果我们添加 "all_frames":true 然后 chrome 浏览器将评估每个 iframe 上的内容脚本,它解决了我的要求。通过访问文档对象从内容脚本中注入脚本。

欲了解更多信息:access iframe content from a chrome's extension content script

注意:我仍然不知道为什么我会遇到跨域问题。

【讨论】:

  • 因为附加脚本标签会创建一个没有提升权限的页面脚本
猜你喜欢
  • 2013-03-05
  • 1970-01-01
  • 2017-03-29
  • 1970-01-01
  • 2012-03-12
  • 2012-12-11
相关资源
最近更新 更多