Protocol on wrapping youtube api in an iframe sandbox to solve security concern









up vote
0
down vote

favorite












My website has a youtube player which uses the Youtube API to create an iframe and swap out the empty div with the iframe. This has been identified as a security risk because the youtube API has externally hosted code and also has access to possible personal information on my website.



The proposed solution would be to wrap an iframe sandbox around the youtube player iframe (iframe within an iframe sandbox). This has been a really difficult topic to research because youtube already uses an iframe, so the search results are diluted. I haven't found any instance of people actually doing this, but it seems like a viable solution.



I'm thinking the best way forward would be to create the iframe sandbox, then use javascript injection to inject the youtube api iframe into the iframe sandbox. Are people doing this at all?



Another possible solution would be to download the youtube player api code locally so it can be controlled by my company. But the issues there are that youtube could update their api and I wouldn't have the updated code, therefore breaking my site.










share|improve this question

























    up vote
    0
    down vote

    favorite












    My website has a youtube player which uses the Youtube API to create an iframe and swap out the empty div with the iframe. This has been identified as a security risk because the youtube API has externally hosted code and also has access to possible personal information on my website.



    The proposed solution would be to wrap an iframe sandbox around the youtube player iframe (iframe within an iframe sandbox). This has been a really difficult topic to research because youtube already uses an iframe, so the search results are diluted. I haven't found any instance of people actually doing this, but it seems like a viable solution.



    I'm thinking the best way forward would be to create the iframe sandbox, then use javascript injection to inject the youtube api iframe into the iframe sandbox. Are people doing this at all?



    Another possible solution would be to download the youtube player api code locally so it can be controlled by my company. But the issues there are that youtube could update their api and I wouldn't have the updated code, therefore breaking my site.










    share|improve this question























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      My website has a youtube player which uses the Youtube API to create an iframe and swap out the empty div with the iframe. This has been identified as a security risk because the youtube API has externally hosted code and also has access to possible personal information on my website.



      The proposed solution would be to wrap an iframe sandbox around the youtube player iframe (iframe within an iframe sandbox). This has been a really difficult topic to research because youtube already uses an iframe, so the search results are diluted. I haven't found any instance of people actually doing this, but it seems like a viable solution.



      I'm thinking the best way forward would be to create the iframe sandbox, then use javascript injection to inject the youtube api iframe into the iframe sandbox. Are people doing this at all?



      Another possible solution would be to download the youtube player api code locally so it can be controlled by my company. But the issues there are that youtube could update their api and I wouldn't have the updated code, therefore breaking my site.










      share|improve this question













      My website has a youtube player which uses the Youtube API to create an iframe and swap out the empty div with the iframe. This has been identified as a security risk because the youtube API has externally hosted code and also has access to possible personal information on my website.



      The proposed solution would be to wrap an iframe sandbox around the youtube player iframe (iframe within an iframe sandbox). This has been a really difficult topic to research because youtube already uses an iframe, so the search results are diluted. I haven't found any instance of people actually doing this, but it seems like a viable solution.



      I'm thinking the best way forward would be to create the iframe sandbox, then use javascript injection to inject the youtube api iframe into the iframe sandbox. Are people doing this at all?



      Another possible solution would be to download the youtube player api code locally so it can be controlled by my company. But the issues there are that youtube could update their api and I wouldn't have the updated code, therefore breaking my site.







      javascript html iframe youtube sandbox






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 9 at 23:45









      Grant Evans

      62




      62



























          active

          oldest

          votes











          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53234683%2fprotocol-on-wrapping-youtube-api-in-an-iframe-sandbox-to-solve-security-concern%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown






























          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















           

          draft saved


          draft discarded















































           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53234683%2fprotocol-on-wrapping-youtube-api-in-an-iframe-sandbox-to-solve-security-concern%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Darth Vader #20

          How to how show current date and time by default on contact form 7 in WordPress without taking input from user in datetimepicker

          Ondo