"use strict"; function handleRequest(request, response) { response.setHeader("Content-Type", "html", false); // Check the params and set the cross-origin-opener policy headers if needed const query = new URLSearchParams(request.queryString); if (query.get("crossOriginIsolated") === "true") { response.setHeader("Cross-Origin-Opener-Policy", "same-origin", false); } // We always want the iframe to have a different host from the top-level document. const iframeHost = request.host === "example.com" ? "example.org" : "example.com"; const iframeOrigin = `${request.scheme}://${iframeHost}`; const IFRAME_HTML = `

Iframe

`; const HTML = `

Top-level document

`; response.write(HTML); }