# iframe

> higher level api for creating and using iframes in browsers

Latest version **1.0.0** (published 2016-04-09) · BSD license · 0 weekly downloads

## Install

```sh
npm install iframe
pnpm add iframe
yarn add iframe
bun add iframe
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2016-04-09 |
| First published | 2013-02-04 |
| Weekly downloads | 0 |
| License | BSD |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 39 |
| Author | max ogden |
| Maintainers | tehshrike |

## Links

- npm: https://www.npmjs.com/package/iframe
- Repository: https://github.com/npm-dom/iframe
- Issues: https://github.com/npm-dom/iframe/issues
- npm.io page: https://npm.io/package/iframe

## Recent versions

- 1.0.0 (latest) — 2016-04-09
- 0.0.1-security — 2016-03-23
- 2.0.0 — 2016-03-22
- 0.3.1 — 2015-02-02
- 0.3.0 — 2014-10-20
- 0.2.0 — 2014-09-05
- 0.1.3 — 2014-06-05
- 0.1.2 — 2014-01-01
- 0.1.1 — 2014-01-01
- 0.1.0 — 2014-01-01
- 0.0.2 — 2013-02-05
- 0.0.1 — 2013-02-04

## README

# iframe

higher level api for creating and removing iframes in browsers

[![browser support](https://ci.testling.com/npm-dom/iframe.png)](https://ci.testling.com/npm-dom/iframe)

[![NPM](https://nodei.co/npm/iframe.png)](https://nodei.co/npm/iframe/)

## usage

use with [browserify](http://browserify.org)

```
npm install iframe
```

```javascript
var iframe = require('iframe')

// creates a new iframe and appends it to the container
frame = iframe({ container: document.querySelector('#container') , body: "hi" })

// completely removes previous iframe from container and generates a new one
frame.setHTML({ body: "bye" })
```

## options

you can pass this into the constructor or `setHTML`

```
{
  name: name of the iframe,
  src: if src url is passed in use that (this mode ignores body/head/html options),
  body: string contents for `<body>`
  head: string contents for `<head>`
  html: string contents for entire iframe
  container: (constructor only) dom element to append iframe to, default = document.body
  sandboxAttributes: array of capability flag strings, default = ['allow-scripts']
  scrollingDisabled: (constructor only) boolean for the iframe scrolling attr
}
```

you can also just pass in a string and it will be used as `{html: 'yourstring'}`

### security

by default the sandbox attribute is set with 'allow-scripts' enabled. pass in an array of capability flag strings. [Available flags](http://www.html5rocks.com/en/tutorials/security/sandboxed-iframes/):
```
allow-forms allows form submission.
allow-popups allows (shock!) popups.
allow-pointer-lock allows (surprise!) pointer lock.
allow-same-origin allows the document to maintain its origin; pages loaded from https://example.com/ will retain access to that origin’s data.
allow-scripts allows JavaScript execution, and also allows features to trigger automatically (as they’d be trivial to implement via JavaScript).
allow-top-navigation allows the document to break out of the frame by navigating the top-level window.
```

## gotchas

iframes are weird. here are some things I use to fix weirdness:

### loading javascript into iframes

```javascript
// setTimeout is because iframes report inaccurate window.innerWidth/innerHeight, even after DOMContentLoaded!
var body = '<script type="text/javascript"> setTimeout(function(){' + javascriptCodeHere + '}, 0)</script>'
```

### getting rid of dumb iframe default styles

```javascript
var head = "<style type='text/css'> html, body { margin: 0; padding: 0; border: 0; } </style>"
```

## license

BSD

---
_Source: https://npm.io/package/iframe · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
