3 ms·
JavaScript is subject to CORS, but "opener" isn't generally, except in Edge. Even then, there is a risk of being surprised. If you open a page on the same site
by parenthephobia 9y ago
JavaScript is subject to CORS, but "opener" isn't generally, except in Edge.
Even then, there is a risk of being surprised. If you open a page on the same site, you may expect that scripts on the opened page can't access the opening page: but because of CORS they can.
Here's a fiddle with a link to another fiddle that copies the contents of a password field from the first fiddle: https://jsfiddle.net/u6rmc49c/3/ https://jsfiddle.net/u6rmc49c/3/