From 2e7a11d332db79cc52ccda00455a15f4dc6147ff Mon Sep 17 00:00:00 2001 From: Peter Ivanov Date: Mon, 28 Feb 2022 14:00:55 +0200 Subject: [PATCH] update --- modules/addons/microweber_addon/order/embed.js | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/modules/addons/microweber_addon/order/embed.js b/modules/addons/microweber_addon/order/embed.js index 53fecb4..12bf37d 100644 --- a/modules/addons/microweber_addon/order/embed.js +++ b/modules/addons/microweber_addon/order/embed.js @@ -64,6 +64,15 @@ document.addEventListener("DOMContentLoaded", function(event) { if (typeof windowhash === 'string' && windowhash.indexOf('frameurl=') > -1) { var hash = windowhash.split('frameurl=')[1]; var hash = decodeURI(atob(hash)) + var domain_check = (new URL(hash)); + domain_check = domain_check.hostname; + + if(window.location.hostname != domain_check){ + alert('You are trying to load a domain search from a different domain. Please use the same domain.'); + return; + } + + // iframe.src = hash; } else {