Not an area I’m familiar with, but this user says no:
news.ycombinator.com/item?id=40918052
lashkari 5 hours ago | prev | next [–]
If it’s really accessible from *.google.com, wouldn’t this be simple to verify/exploit by using Google Sites (they publish your site to sites.google.com/view/<sitename>)?
DownrightNifty 5 hours ago | parent | next [–]
JS on Google Sites, Apps Script, etc. runs on *.googleusercontent.com, otherwise cookie-stealing XSS >happens.
Andromxda@lemmy.dbzer0.com 4 months ago
You can check this yourself. Just paste this into the developer console:
If you get a return like this, it means that the site has special access to these private, undocumented APIs