/** * The frame resize protocol — ONE implementation, both frames. * * Every Vendo iframe (the served app's http frame, the box app template) lets a * document the host cannot see report its own natural height. The identity gate * is the security half of that, and a second copy of a security gate is a * second gate to get wrong — so the gate, the message validation, and the clamp * live here and nowhere else. * * The wire: the framed document posts `{ vendo: true, kind: "resize", height }` * to its parent (`postToHost` in embedded-runtime.ts stamps every message), and * the host fits the frame to it. */ /** * The ceiling a host that configures nothing gets, kept to the pixel so no * shipped host's behaviour changes. */ export declare const DEFAULT_FRAME_MAX_HEIGHT = 8192; /** * The identity gate. `event.source` is the window that actually sent the * message, and it is the one thing a sender cannot forge — only the frame we * rendered may speak for that frame. Every other window (the host page, another * embed, an ad frame, an opener) is ignored in silence. */ export declare function isFromFrame(frame: HTMLIFrameElement | null, event: MessageEvent): boolean; /** * The one resize handler both frames install: identity gate, then validation, * then the host's bounds, then apply. Returns whether the frame was resized, so * a caller with other message kinds can use it as an arm of its own chain. */ export declare function applyFrameResize(frame: HTMLIFrameElement | null, event: MessageEvent): boolean; /** * The ceiling declaration both frames carry. It is load-bearing CSS (the browser * enforces it whatever height we write) and it is what `clampToHostBounds` reads * back, so the host has exactly one place to change: the custom property. */ export declare const FRAME_MAX_HEIGHT_CSS = "var(--vendo-app-frame-max-height, 8192px)";