The window.postMessage envelope the embedded iframe sends to its host
page. The embed script consumes these and re-dispatches them as DOM
events; listen for the postMessage directly only if you are building your
own host-side plumbing instead of using the provided custom elements —
and always check source === EMBED_MESSAGE_SOURCE AND the message origin
before trusting one.
The
window.postMessageenvelope the embedded iframe sends to its host page. The embed script consumes these and re-dispatches them as DOM events; listen for the postMessage directly only if you are building your own host-side plumbing instead of using the provided custom elements — and always checksource === EMBED_MESSAGE_SOURCEAND the message origin before trusting one.