malloy-html-data-app-embedding
Installation
SKILL.md
Embedding an HTML Data App
Publisher.embed(selector, { src })drops a package page into a host page as a sandboxed, auto-resizing iframe. Same-origin embeds authenticate with the browser's cookies; cross-origin embeds need a signed token.
The host-page pattern
<script src="https://your-publisher/sdk/publisher.js"></script>
<div id="dashboard"></div>
<script>
const handle = Publisher.embed("#dashboard", {
src: "https://your-publisher/environments/demo/packages/sales/index.html",
});
// handle.destroy() removes the iframe and detaches its listeners.
</script>
embed(selector, options) returns { iframe, destroy() }. Options: src (required), token (a signed token for cross-origin auth, appended as embed_token), height (omit to auto-size; a number is treated as pixels), and allow (the iframe permissions policy).