Browse files

@abarth's feedback.

* e.origin === sandboxedFrame.contentWindow
  • Loading branch information...
1 parent 884a4c2 commit 049c0142b4653a557b135ba5058b24924b49d409 @mikewest committed Jan 8, 2013
Showing with 3 additions and 2 deletions.
  1. +3 −2 static/demos/evalbox/index.html
View
5 static/demos/evalbox/index.html
@@ -84,8 +84,9 @@
// header have "null" rather than a valid origin. This means you still
// have to be careful about accepting data via the messaging API you
// create. Check that source, and validate those inputs!
- if ((e.origin === "null" && e.source === sandboxedFrame)
- || (e.origin === (window.location.protocol + "//" + window.location.host) && e.source === unsandboxedFrame) {
+ if ((e.origin === "null" && e.source === sandboxedFrame.contentWindow)
+ || (e.origin === (window.location.protocol + "//" + window.location.host)
+ && e.source === unsandboxedFrame.contentWindow)) {
alert('Result: ' + e.data);
}
});

0 comments on commit 049c014

Please sign in to comment.