How to use this reference
Document the expected sender, operation, recipient and permitted data for browser messages. Review identity checks, data validation, application authorization and rendering safety separately in owned application designs.
Before reading
- Basic browser origin and document concepts
- Familiarity with event-driven JavaScript
Context and limits
- Living guidance; review supported browser behavior and application context before implementation.
- Origin and format validation do not by themselves define which business operations or disclosures are authorized.
Sources and provenance
- HTML5 Security Cheat Sheet: Web Messaging OWASP Cheat Sheet Series · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.