Leaking the top-level window.location.href by accessing the document.baseURI of a sandboxed iframe with a srcdoc!

Credit for this one goes to the one and only Johan Carlsson!