set security=restricted attribute on the iframe, preventing javascript