An embedded interface is a separate document with its own origin, lifecycle, storage behavior, and failure modes. Treat the frame as an integration boundary rather than a child component. This track follows a private inspection report that opens a supplier viewer and receives a selected reference. It covers frame capabilities, message validation, channel lifetimes, popup returns, and a usable fallback when embedding is blocked. The host keeps authority over case data; the embedded document receives only the minimum context for the current task.
Topics in this track
- Frame Sandbox, Capabilities, and Fallback — Give an embedded document only the browser powers its task requires and preserve a non-frame path.
- Cross-Window Messages: Origin, Source, Schema, and Replay — Accept a frame message only from the expected document and only for the current interaction.
- MessageChannel Lifetime and Request Correlation — Use a dedicated port for a bounded conversation and close it when the frame changes or the task ends.
- Popup Handoff, Return, and Window Ownership — Separate a user-initiated external handoff from the server-confirmed result and its fallback route.
Prerequisite paths
Embedding and Browser Capability Headers; Privacy-Aware External Integrations.
Neighbor track
Frontend Build and Artifact Integrity.
Practice path
Build Project: embedded attachment viewer contract and check decisions in Web Development: embedded interfaces and build integrity quiz.
