5 ms·
In Opera 12, I killed "window.opener" by replacing the "opener" string with "opera" in the opera.dll. This way it gets overwritten by the normal window.opera va
by Grom_PE 9y ago
In Opera 12, I killed "window.opener" by replacing the "opener" string with "opera" in the opera.dll. This way it gets overwritten by the normal window.opera variable and is essentially hidden. So far I haven't encountered a site legitimately relying on this variable.
- username223 9y agoAdmirably thuggish! I remember doing something similar, replacing "__gnu_warning" with "__gnu_whining" in libc.so to eliminate whining about using "gets()" in throwaway programs.
- fivesigma 9y agoA legitimate usage case would be opening a login popup on another domain that can't be iframe'd. For example OAuth social network login popups. They require window.opener to send back login credentials to the original website.
- mygo 9y agoWindow.opener isn’t your problem. Window.opener is sandboxed by CORS. And you need it for things such as oAuth. Target=“_blank” is your problem. That’s where Window.opener gets exposed. You’re better off finding the “_blank” definition and renaming it so that it’s never triggered, or assigning it to the definition of “self”, etc.
- Grom_PE 9y agoKilling off "_blank" would disable force-opening links in a new window, which is useful in dynamic context, e.g. chat page, so I don't want that. Also, window.opener is still abusable if I middle-click links to open in a new tab. I was very surprised when my Google Search tab got replaced by something else after I middle-clicked on some questionable link.