Once the browser can be sure of the origin of a a document or web worker (when the blocking bugs are fixed), IPCs communicating that origin to the browser should be updated to omit the origin and the browser should instead use the origin it knows is the originator of the request. If the origin is not the same as the origin of the content, the browser should at least check the supplied origin is valid for the particular renderer process.
This includes migrating renderer-process-wide interfaces that should be origin-scoped to be per-ExecutionContext (frame or worker).
This is a tracking bug for updating all the IPCs.
Comment 1 by lukasza@chromium.org
, Nov 6 2017