Skip to main content
WolfShade
Legend
July 2, 2018
Question

Facebook, YouTube API security issue

  • July 2, 2018
  • 1 reply
  • 284 views

Hello, all,

I've recently been tasked to investigate using Twitter, Facebook, and YouTube APIs on our public-facing page. I have been looking into it, and the Twitter API is very simple - they even have a page that you can use to customise the look and feel of whatever page you wish to grab tweets from and it creates an anchor tag with all the parameters. Very nice.

However, I have come across a stumbling block. The Facebook and YouTube APIs involve using IFRAME. On our network, IFRAME is proscribed. Major security issue (primarily cross-site scripting.)

Is anyone aware of alternative methods for putting a Facebook or YouTube widget on a site that does NOT use IFRAME?

V/r,

^ _ ^

    This topic has been closed for replies.

    1 reply

    WolfShade
    WolfShadeAuthor
    Legend
    July 2, 2018

    I did find a non-iframe method, here, but it's not displaying anything.  Anyone have any suggestions?

    V/r,

    ^ _ ^