Use window.open but block use of window.opener
09:52 14 Nov 2016

A while back I ran across an interesting security hole

Link

Looks innocuous enough, but there's a hole because, by default, the page that's being opened is allowing the opened page to call back into it via window.opener. There are some restrictions, being cross-domain, but there's still some mischief that can be done

window.opener.location = 'http://gotcha.badstuff';

Now, HTML has a workaround

Link

That prevents the new window from having window.opener passed to it. That's fine and good for HTML, but what if you're using window.open?


How would you block the use of window.opener being passed here?

javascript cross-domain