An <iframe> source the document may carry: https only, on a known player
host or one the integrator allowlisted. Returns the normalised URL or null.
This is the single gate for frames. The HTML parser lets <iframe>
through only because the schema declares a rule for it, and that rule
defers to this function.
An
<iframe>source the document may carry: https only, on a known player host or one the integrator allowlisted. Returns the normalised URL or null. This is the single gate for frames. The HTML parser lets<iframe>through only because the schema declares a rule for it, and that rule defers to this function.