Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Limit oidc check session iframe postMessage hook scope
In certain cases the check session iframe might receive postMessage events from itself. This might sound strange and normally does not happen expect in cases where other scripts run in the scope of this iframe (e.g. getting injected by a browser extension). This for example happens with the 1Password browser extension which seems to communicate with itself via postMessage to itself and causes a high CPU load as an event busy loop is created. With this change, our own processing of events is only done if the event source is not the own window (which is the only case we care about anyways).
- Loading branch information