W3C home > Mailing lists > Public > www-style@w3.org > January 2016

Allow auto-resize on iframe

From: Craig Francis <craig.francis@gmail.com>
Date: Tue, 26 Jan 2016 16:00:18 +0000
Message-Id: <A700E512-20DF-4276-ABD1-719FBB032071@gmail.com>
To: www-style@w3.org
Considering the recent removal of <iframe seamless>...

I've made a suggestion on the WHATWG issue log regarding what I consider the main use of @seamless on iframes.

Anne van Kesteren suggested I post that idea here:


Copy below.



Considering the removal of <iframe seamless> on issue #331.


For me, the main feature of @seamless was the ability for the iframe to resize based on the size of the child document (really just the height), so no scroll bars would appear.

Currently this is "solved" with the use of some very messy JavaScript:


Which is more difficult cross-origin, which needs postMessage and custom JS running on every single page (both child and parent).

The suggestion of Shadow-DOM is interesting, but I don't believe this provides the same level of protection (and backwards compatibility), as often the child content is put in an iframe to keep it isolated from the current page (i.e. for security reasons).

Typically I put things in an iframe because they could easily be malicious, and I would really like to use asandbox to block allow-scripts.


zcorpan commented...

For cross-origin I suppose the embeddee would need to opt-in somehow (e.g. meta tag), to not expose new information cross-origin.

Received on Tuesday, 26 January 2016 16:00:45 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 22:52:34 UTC