The H5 page on the mobile side was inexplicably added an iframe tag to the top, covering my original element, has anyone ever encountered it?


the simplest thing is to change it to https

at first, I also thought HTTPS was the easiest, until I found CSP . So since then, I have been recommending things for my own use, don't bother to do anything cross-domain, just set up an agent and stop it; then anyone who wants to play injection can use CSP to block it.

in addition, if you think MDN is too messy, you can also take a look at the following two articles:

of course, this is not a complete negation of the best combination of HTTPS,.

you will experience the wonderful use of iframe in ios
