Skip to content

Archive

Web Platform

2 articles
Cybersecurity 16 Sep 2026 9 min read

Cross-Origin Opener Policy Separates Window Relationships at the Browsing Context Boundary

Cross-Origin Opener Policy Separates Window Relationships at the Browsing Context Boundary A browser can prevent a cross-origin popup from reading most properties of its opener and still preserve a live relationship between the two windows. The same-origin policy restricts direct access to a foreign document, but a cross-origin WindowProxy can remain reachable, expose a limited interface, participate in navigation relationships, and carry observable state such as whether the referenced window is closed.

Cybersecurity 15 Sep 2026 6 min read

Permissions Policy Bounds Browser Feature Authority

Permissions Policy Bounds Browser Feature Authority A page can embed code from several origins while still presenting a single application surface. That composition becomes security-relevant when browser capabilities such as geolocation, camera access, microphone access, fullscreen, or payment functions are available inside the resulting document tree. The code that renders a widget may not need the same browser authority as the application that hosts it. Permissions Policy gives a site a way to restrict selected web-platform features by origin and frame. It is not a replacement for user permission prompts, sandboxing, application authorization, or browser isolation. Its value is narrower and architectural: it can remove capabilities from documents that have no legitimate reason to exercise them.