Skip to content

Decide how to treat CSP sandbox in COOP #4921

@shhnjk

Description

@shhnjk

Any origin served with CSP sandbox (without allow-same-origin) will have opaque origin. But until that response header comes back, browser would not know its origin.

We should probably treat CSP sandboxed page as cross-origin even though the tuple of scheme, host, and port would match. But is it same-site or cross-site?

Metadata

Metadata

Assignees

No one assigned

    Labels

    security/privacyThere are security or privacy implicationstopic: cross-origin-opener-policyIssues and ideas around the new "inverse of rel=noopener" header

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions