3 ms·
Cross-origin window.opener objects are not full window objects. You can test this out on any browser - the most they can do is what the articles you linked to s
by mediumdeviation 10y ago
Cross-origin window.opener objects are not full window objects. You can test this out on any browser - the most they can do is what the articles you linked to says - redirect the parent window, which can be used for phishing, but is otherwise relatively harmless.