github web-platform-tests/wpt merge_pr_48213

latest releases: merge_pr_49470, epochs/three_hourly/2024-12-03_06H, epochs/six_hourly/2024-12-03_06H...
4 months ago

[Partitioned Popins] Popin-Policy Response Header (Default none)

Every top-frame response for a popin must include a Popin-Policy header
that permits the popin's opener's top-frame-origin. This is to ensure
popins cannot be opened in a partitioned context other than the one they
are designed to.

This CL requires the header to exist and permit access, whereas before
omitting the header would permit access.

Explainer: https://explainers-by-googlers.github.io/partitioned-popins/
I2P: https://groups.google.com/a/chromium.org/g/blink-dev/c/ApU_zUmpQ2g/

Bug: 340606651
Change-Id: I4577cefe3687c1cf0501a4c195161f1335d8023b
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/5865610
Reviewed-by: Dana Fried dfried@chromium.org
Auto-Submit: Ari Chivukula arichiv@chromium.org
Commit-Queue: Rakina Zata Amni rakina@chromium.org
Reviewed-by: Rakina Zata Amni rakina@chromium.org
Cr-Commit-Position: refs/heads/main@{#1356212}

Don't miss a new wpt release

NewReleases is sending notifications on new releases.