How diagrams are sandboxed
Diagram HTML runs in a sandbox with an opaque origin, so a diagram's scripts can't read your session or act as you. What works and what doesn't inside a diagram.
Diagram treats every diagram's HTML as untrusted, including your own. It's never rendered as part of a Diagram page.
https://diagram.la/<id>shows the diagram in an<iframe>with thesandboxattribute.- The frame loads
https://diagram.la/<id>/raw, which is sent with aContent-Security-Policy: sandboxheader, so it stays sandboxed even when opened directly. - The sandbox gives the diagram an opaque origin. Its scripts can't read Diagram's cookies, can't call the API as the viewer, and can't reach the page around it.
What works inside a diagram
- Inline
<script>and<style>, and scripts, styles, fonts, and images loaded from other sites such as a CDN. - SVG, canvas, CSS animation, and click, hover, and zoom interactions.
- Links that open in a new tab.
What doesn't
- Forms. Submitting them is blocked.
- Cookies,
localStorage,sessionStorage, and IndexedDB. Scripts that touch them will throw, so wrap that code intry/catch. - Top-level navigation, and framing the diagram from other sites.
- Files next to the HTML in your repo. Inline them or load them from a URL.
Accounts and keys
- Sign-in is Google only. The session is an httpOnly cookie.
- API keys are stored as SHA-256 hashes, shown once, and can be revoked on the API keys page. Each key acts as the account that created it.
- Only a project's owner can see and change it, plus the emails the owner adds as members, who can only read. Nobody else, including Diagram's own staff accounts, can list or open a private diagram. A public diagram opens for anyone with its exact link.