﻿id	summary	reporter	owner	description	type	status	component	version	severity	resolution	keywords	cc	stage	has_patch	needs_docs	needs_tests	needs_better_patch	easy	ui_ux
37394	System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-popups	venkatchalla06		"`check_cross_origin_opener_policy` (in `django/core/checks/security/base.py`) validates `SECURE_CROSS_ORIGIN_OPENER_POLICY` against `CROSS_ORIGIN_OPENER_POLICY_VALUES`, which currently lists only `same-origin`, `same-origin-allow-popups`, and `unsafe-none`, and raises `security.E024` (an Error) for any other value.

The HTML standard defines a fourth `Cross-Origin-Opener-Policy` value, `noopener-allow-popups`, supported by Chrome and Safari. It severs the opener relationship even for same-origin popups, providing stronger isolation than `same-origin-allow-popups`.

Because the value is missing from the allow-list, a project that sets the valid, more-hardened `SECURE_CROSS_ORIGIN_OPENER_POLICY = ""noopener-allow-popups""` fails `manage.py check --deploy` with `security.E024`, even though `SecurityMiddleware` emits the header correctly at runtime.

Proposed fix: add `""noopener-allow-popups""` to `CROSS_ORIGIN_OPENER_POLICY_VALUES`. A patch with a test and docs (versionadded 6.2) is ready.

Reference: https://html.spec.whatwg.org/multipage/browsers.html#cross-origin-opener-policies"	Bug	new	Core (System checks)	dev	Normal			venkatchalla06	Unreviewed	0	0	0	0	0	0
