Opened 2 hours ago
#37394 new Bug
System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-popups
| Reported by: | venkatchalla06 | Owned by: | |
|---|---|---|---|
| Component: | Core (System checks) | Version: | dev |
| Severity: | Normal | Keywords: | |
| Cc: | venkatchalla06 | Triage Stage: | Unreviewed |
| Has patch: | no | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
check_cross_origin_opener_policy (in django/core/checks/security/base.py) validates SECURE_CROSS_ORIGIN_OPENER_POLICY against CROSS_ORIGIN_OPENER_POLICY_VALUES, which currently lists only same-origin, same-origin-allow-popups, and unsafe-none, and raises security.E024 (an Error) for any other value.
The HTML standard defines a fourth Cross-Origin-Opener-Policy value, noopener-allow-popups, supported by Chrome and Safari. It severs the opener relationship even for same-origin popups, providing stronger isolation than same-origin-allow-popups.
Because the value is missing from the allow-list, a project that sets the valid, more-hardened SECURE_CROSS_ORIGIN_OPENER_POLICY = "noopener-allow-popups" fails manage.py check --deploy with security.E024, even though SecurityMiddleware emits the header correctly at runtime.
Proposed fix: add "noopener-allow-popups" to CROSS_ORIGIN_OPENER_POLICY_VALUES. A patch with a test and docs (versionadded 6.2) is ready.
Reference: https://html.spec.whatwg.org/multipage/browsers.html#cross-origin-opener-policies