https://systw.net/note/archives/1250
DOM XSS in third-party