2 ms·
> I never found a way for a server to check if the originating request is for an iframe or a new tab. There is no such technique. One way to distinguish is to
by simpaticoder 3y ago
> I never found a way for a server to check if the originating request is for an iframe or a new tab.
There is no such technique. One way to distinguish is to pick a URL convention and modify the URL (before the hash) of the iframe URL. For example, add ?iframe=true to the URL, and then have the server check for that. Perhaps more usefully you could include information about the parent URL, e.g. url += '?parent=${document.referrer}'. Or something.
- niutech 3y agoThere is a new request header: `Sec-Fetch-Dest: iframe`
- sesm 3y agoCan we add a cookie instead of modifying URLs?
- simpaticoder 3y agoNo. The same cookies are added to both the host and guest pages.
- nymanjon 3y agoI would think you could add a cookie with JS. Then you know JS is being used. So, that does seem viable.