New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 682211 link

Starred by 1 user

Issue metadata

Status: Archived
Owner: ----
Closed: Jan 10
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

consider marking secure sites that receive messages from insecure sites as insecure

Project Member Reported by jochen@chromium.org, Jan 18 2017

Issue description

maybe even if they have a message handler?

Or just block postMessage from insecure to secure top-level?

postMessage from insecure to secure appears to be pretty common: https://www.chromestatus.com/metrics/feature/timeline/popularity/420 however, when an insecure top-level wants to postMessage to a secure iframe, that's probably fine
 

Comment 1 by jochen@chromium.org, Jan 18 2017

Cc: f...@chromium.org emilyschechter@chromium.org
Status: Archived (was: Untriaged)
Archiving P3s older than 1 year with no owner or component.

Sign in to add a comment