1/******************************************************************** 2 Host-side script for the plateforme-accueil iframe: 3 4 1. sizes it to its content, and publishes back the band of it that is on 5 screen, so the embedded page can place a modal where the visitor is 6 looking. 7 8 The iframe is sandboxed without allow-same-origin, so its document sits in 9 an opaque origin that no concrete targetOrigin can match. Hence "*", which 10 is safe here: the message only reaches this frame, and frame-src decides 11 what may load in it. It carries no secret either way. 12 13 2. receives analytics events from the iframe and forwards them to Matomo 14 (when user has consented to tracking). 15********************************************************************/ 16"use strict"; 17 18(function () { 19 window._paq = window._paq || []; // Matomo command queue. 20 21 const frame = document.getElementById("plateforme-accueil-iframe"); 22 // https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/iframe#error_and_load_event_behavior 23 let frameLoaded = false; 24 let frameHeight = null; 25 26 function publishViewport() { 27 var rect = frame.getBoundingClientRect(); 28 var top = Math.max(0, -rect.top); 29 const remainingHeight = rect.height - top; 30 const height = Math.round( 31 Math.max(0, Math.min(window.innerHeight, Math.round(remainingHeight))), 32 ); 33 // Off screen, or unchanged: nothing worth posting. 34 if (height === 0 || frameHeight === height) { 35 return; 36 } 37 frameHeight = height; 38 frame.contentWindow.postMessage( 39 { 40 source: "plateforme-accueil-iframe-hote", 41 type: "viewport", 42 top: top, 43 height: height, 44 }, 45 "*", 46 ); 47 } 48 49 let scheduled = null; 50 function schedule() { 51 if (scheduled === null) { 52 scheduled = window.requestAnimationFrame(function () { 53 scheduled = null; 54 publishViewport(); 55 }); 56 } 57 } 58 59 window.addEventListener("message", function (evt) { 60 const data = evt.data; 61 if ( 62 !data || 63 data.source !== "plateforme-accueil-iframe-contenu" || 64 frame.contentWindow !== evt.source 65 ) { 66 return; 67 } 68 switch (data.type) { 69 case "analytics": 70 window._paq.push([ 71 "trackEvent", 72 data.matomoCategory, 73 data.matomoAction, 74 data.matomoName, 75 ]); 76 break; 77 case "resize": 78 frameLoaded = true; 79 frame.style.height = data.height + "px"; 80 schedule(); 81 break; 82 } 83 }); 84 // The iframe must not load before the listener above is installed to 85 // catch the first resize message. 86 frame.src = frame.dataset.plateformeAccueil; 87 88 window.addEventListener("scroll", schedule, { passive: true }); 89 window.addEventListener("resize", schedule); 90 window.addEventListener("load", schedule); 91 92 setTimeout(function () { 93 if (!frameLoaded) { 94 document 95 .getElementById("loading-error-fallback") 96 .classList.remove("d-none"); 97 frame.classList.add("d-none"); 98 window._paq.push([ 99 "trackEvent", 100 "iframe", 101 "load-failure", 102 "plateforme-accueil", 103 ]); 104 } 105 }, 10000); 106})();
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.