How does optimizely allow cross domain event listeners?

  • They iframe does not contain content from a 3rd party domain. They proxy content through their domain:

        <iframe src="http://edit.optimizely.com/http://google.com?optimizely_compatibility=false&amp;optimizely_disable=true&amp;optimizely_load_script=https%3A%2F%2Fwww.optimizely.com%2Fjs%2Finnie-www-master-1092.366954744303823947.js&amp;optimizely_log=false&amp;optimizely_cache_buster=1367272480789"></iframe>