Consider making X-Frame-Options: deny
to create a new browsing context group
#4218
Labels
X-Frame-Options: deny
to create a new browsing context group
#4218
While exploring the latest proposal in #3740, we came to realization that much of the security benefits & needs of the header coincides with that of
X-Frame-Options: deny
with regards to severing opener and creating a new namespace for frames, etc..Namely, websites that opts to set
X-Frame-Options: deny
often don't want other websites to be able to click jack, be able to navigate frames within the website, etc... We think almost all websites that currently opts to useX-Frame-Options: deny
also want to sever opener relationship as well if they could.Therefore we propose to make
X-Frame-Options: deny
sever the opener relationship by creating a new browsing context group as well, and we intend to experiment this behavior in WebKit.The text was updated successfully, but these errors were encountered: