All boils down the sender using a specific target, and the receiver remembering to check the origin.
http://www.riskcompletefailure.com/2013/03/postmessage-oauth...
All boils down the sender using a specific target, and the receiver remembering to check the origin.