I'm going to have several iframes on my page and I'm going to quite intensively use sessionStorage inside them. What I'm curious about is if I will have separate storages or one shared for all iframes? How do the size limits apply?
相关问题
- Is there a limit to how many levels you can nest i
- How to toggle on Order in ReactJS
- void before promise syntax
- Keeping track of variable instances
- Can php detect if javascript is on or not?
OK, I've made a test myself. At least in Chrome (44) and Firefox (40) the sessionStorage is shared among page and the iframes included if they are of the same domain and do not if they are of different domains.
If sessionStorage is shared depends on the iframe's page and it's origin, which is the domain part of the URL. If you have a webpage at
http://myserver/test.html
and it is includinghttp://thatserver/some.html
via an iframe, the iframe's page has the domainthatserver
. Thus the origin differs and the sessionStorage won't be shared. But if the iframe's page ishttp://myserver/some.html
it has the same origin and therefore will share the same session storage.Now there is an additional trick: The sandbox attribute for the iframe. If you write
<iframe sandbox>
without the valueallow-same-origin
the content of the iframe gets a unique origin. That means it would get a different sessionStorage regardless of the real origin that page has. You can write<iframe sandbox="allow-same-origin">
to sandbox the content AND let the content of the iframe to have the same origin (but only if if does have the real same origin).Now special notes: sandboxed iframes won't support localStorage per spec. And in webkit-browsers and mozilla firefox an exception will be thrown if the sandboxed iframe content will try to access sessionStorage.