3 ms·
So should Protonmail (and any other site with similarly sensitive data) be setting that header, then? It’s probably hard to change the default. I bet some use c
by wging 2y ago
So should Protonmail (and any other site with similarly sensitive data) be setting that header, then? It’s probably hard to change the default. I bet some use cases (SSO popups?) depend on it.
- connicpu 2y agoIt's not unreasonable to set a different header value for the login page only, where it should be safe because no external user data is being rendered.
- lxgr 2y agoSites can also opt into the same behavior by setting the rel="noopener" or alternatively target="_blank" attributes on outgoing links (i.e. <a> tags). And yes, something like a webmail site should definitely be setting the header, or at lest these attributes for outbound content links.
- wging 2y agoThat is a little different, though: those attributes are for if you're example.com linking to protonmail, the header is for if you're protonmail deciding on security policies for interactions with example.com.
- lxgr 2y agoThe header works in both directions; cf. the table on https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Opener-Policy https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cr....