Opened 2 hours ago

#37394 new Bug

System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-popups

Reported by: venkatchalla06 Owned by:
Component: Core (System checks) Version: dev
Severity: Normal Keywords:
Cc: venkatchalla06 Triage Stage: Unreviewed
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description

check_cross_origin_opener_policy (in django/core/checks/security/base.py) validates SECURE_CROSS_ORIGIN_OPENER_POLICY against CROSS_ORIGIN_OPENER_POLICY_VALUES, which currently lists only same-origin, same-origin-allow-popups, and unsafe-none, and raises security.E024 (an Error) for any other value.

The HTML standard defines a fourth Cross-Origin-Opener-Policy value, noopener-allow-popups, supported by Chrome and Safari. It severs the opener relationship even for same-origin popups, providing stronger isolation than same-origin-allow-popups.

Because the value is missing from the allow-list, a project that sets the valid, more-hardened SECURE_CROSS_ORIGIN_OPENER_POLICY = "noopener-allow-popups" fails manage.py check --deploy with security.E024, even though SecurityMiddleware emits the header correctly at runtime.

Proposed fix: add "noopener-allow-popups" to CROSS_ORIGIN_OPENER_POLICY_VALUES. A patch with a test and docs (versionadded 6.2) is ready.

Reference: ​https://html.spec.whatwg.org/multipage/browsers.html#cross-origin-opener-policies

Change History (0)

Note: See TracTickets for help on using tickets.
Back to Top