Threads

Prototyping Roam in an iframe past X-Frame-Options

7 tweets · March 2021 · 7 likes · 0 retweets · read on Twitter

Replying to Conor @Conaw ·

@Malcolm_Ocean @thepericulum Pretty sure there’s big security reason

@Conaw @thepericulum Hmm... looking here, it seems it's sort of a suggestion to the browser, so I could at least experiment with this by using a browser extension to ignore X-Frame-Options for roamresearch.com... developer.mozilla.org/en-US/docs/Web…

@Conaw @thepericulum Seems the main security reason is clickjacking, and in principle if there were other domains that were trusted, they could perhaps be whitelisted by not sending the X-Frame-Options header to requests from those domains... Could maybe also just like, disable settings when framed.

@Conaw @thepericulum do be do be do (this is with a browser extension (this one chrome.google.com/webstore/detai… though I loaded it from source not from the store, and am intending to narrow domains it runs on))

@Conaw @thepericulum I can't find the docs for the frontend API though. I want to take the next obvious step and have that "alert" make a new block instead.

@Conaw @thepericulum ahhh well I couldn't find it in the help DBs I looked in (several!) but I just found the window.roamAlphaAPI object and realized it has a createBlock method

@Conaw @thepericulum (Currently I have to click login every time I reload the frame, and since I only have google auth, not password, this probably means a whole nother layer of insecurity required by this chrome extension I'm using. But hey, we're prototyping here.)

@Conaw @thepericulum OH, YEAAHH!