|
|
|
|
|
by nailer
3703 days ago
|
|
> this kind of stuff isn't fixed by a simple browser update and inherited "for free" by all sites Why not? What's stopping browser from disabling window.opener unless CSP specifically allows it? (totally appreciate there may be something I'm missing here, and thanks for responding) |
|
window-ref 'self' PayPal.com
Something like that would let the site reference their own windows as well as grant access to a "trusted partner" like PayPal.