Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
@olasearch/react-frame-portal
Advanced tools
React component to wrap your application or component in an iFrame for encapsulation purposes
This component allows you to encapsulate your entire React application or per component in an iFrame.
npm install --save react-frame-component
import Frame from 'react-frame-component';
Go check out the demo.
const Header = ({ children }) => (
<Frame>
<h1>{children}</h1>
</Frame>
);
ReactDOM.render(<Header>Hello</Header>, document.body);
Or you can wrap it at the render
call.
ReactDOM.render(
<Frame>
<Header>Hello</Header>
</Frame>,
document.body
);
head: PropTypes.node
The head
prop is a dom node that gets inserted before the children of the frame. Note that this is injected into the body of frame (see the blog post for why). This has the benefit of being able to update and works for stylesheets.
initialContent: PropTypes.string
Defaults to '<!DOCTYPE html><html><head></head><body><div></div></body></html>'
The initialContent
props is the initial html injected into frame. It is only injected once, but allows you to insert any html into the frame (e.g. a head tag, script tags, etc). Note that it does not update if you change the prop. Also at least one div is required in the body of the html, which we use to render the react dom into.
mountTarget: PropTypes.string
The mountTarget
props is a css selector (#target/.target) that specifies where in the initialContent
of the iframe, children will be mounted.
<Frame
initialContent='<!DOCTYPE html><html><head></head><body><h1>i wont be changed</h1><div id="mountHere"></div></body></html>'
mountTarget='#mountHere'
>
</Frame>
contentDidMount: PropTypes.func
contentDidUpdate: PropTypes.func
contentDidMount
and contentDidUpdate
are conceptually equivalent to
componentDidMount
and componentDidUpdate
, respecitvely. The reason these are
needed is because internally we call ReactDOM.render
which starts a new set of
lifecycle calls. This set of lifecycle calls are sometimes triggered after the
lifecycle of the parent component, so these callbacks provide a hook to know
when the frame contents are mounted and updated.
The iframe's window
and document
may be accessed via the React context values window
and document
respectively.
const MyComponent = (props, context) => {
const {
document: iframeDocument,
window: iframeWindow
} = context;
return (<...rendered jsx.../>);
};
MyComponent.contextTypes = {
window: PropTypes.any,
document: PropTypes.any
};
I wrote a blog post about building this component.
Copyright 2014, Ryan Seddon. This content is released under the MIT license http://ryanseddon.mit-license.org
FAQs
React component to wrap your application or component in an iFrame for encapsulation purposes
The npm package @olasearch/react-frame-portal receives a total of 2 weekly downloads. As such, @olasearch/react-frame-portal popularity was classified as not popular.
We found that @olasearch/react-frame-portal demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.