by default should allow "window.postMessage", "window.open" "window.addEventListener" "window.removeEventListener"