I'm trying to <iframe sandbox> the youtube iframe_api to prevent it from accessing sensitive data in the main window.
I have a sandboxed iframe that contains the js to invoke the api, but in order to get it to work, I need to give it sandbox="allow-same-origin" which defeats the entire purpose, giving it access to the main window. Please see the simplified codepen example.
https://codepen.io/anon/pen/qLJrxd
Is there another recommendation for sandboxing the API?