Chrome blocks iframe with same origin even with --disable-web-security

Viewed 560

I am on a page with the following domain https://my.example.com

When I type the following in the chrome console: document.querySelector('.my-app-iframe').contentDocument I get null because the iframe src is https://members.example.com

Launching chrome (Using nightwatch.js test runner) with the --disable-web-security flag solves this. I can now access the contentDocument of the iframe and interact with contents.

But then this happens:

document.querySelector('.my-app-iframe') :
<iframe src='https://members.example.com'> //all good

var myFrame = document.querySelector('.my-app-iframe').contentDocument.querySelector('#iframe1') :
<iframe id='myContent' src='/Content/myApp.aspx'>

myFrame.contentDocument.querySelector('#iframe2')
<iframe src='https://my.example.com/index.html'>

Now I want to access one last nested Iframe but I get this:

myFrame.contentDocument.querySelector('#iframe2').contentDocument.querySelector('#iframe3')

Uncaught DOMException: Blocked a frame with origin "https://my.example.com" from accessing a cross-origin frame.

This is weird because I'm starting from a website that's at my.example.com, and since I've disabled web security I can access an iframe with a different origin. But then I'm unable to access another nested iframe with the same domain that im starting from. Why is this happening and what could be a solution?

0 Answers
Related