From 8c769140bb52cb0dd0ededab5886b14c57dfd596 Mon Sep 17 00:00:00 2001 From: Martin McKeaveney Date: Wed, 28 Aug 2024 16:56:51 +0100 Subject: [PATCH] adding conditional to prevent embedprovider handler firing --- packages/client/src/components/context/EmbedProvider.svelte | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/packages/client/src/components/context/EmbedProvider.svelte b/packages/client/src/components/context/EmbedProvider.svelte index 169ac4abe5..16ba615700 100644 --- a/packages/client/src/components/context/EmbedProvider.svelte +++ b/packages/client/src/components/context/EmbedProvider.svelte @@ -12,6 +12,10 @@ } function handleMessage(event) { + if (event.data?.type !== "bb-parent-window-event") { + return + } + // Validate the event origin to ensure it's coming from a trusted source // Allow different subdomains but must match TLD const appOrigin = extractDomainFromUrl(window.location.origin)