Heya,
During our last discussion we briefly reviewed these issues with Cross-Origin-Opener-Policy:
* about:blank handling
* Redirects
* Going back/forward in history
And for Cross-Origin (opting into being loaded by something that may have high-resolution timers):
* How are sites told they are being included?
* Should we require X-Frame-Options? If so, should we have an explicit allow-all?
* Should we separate top-level opt-in from popup/subframe opt-in? (I.e., have different headers.)
* Should Cross-Origin have an effect when it's not specified in conjunction with Cross-Origin-Opener-Policy?
I'll be trying to find suitable answers before the next meeting and will post those in the relevant whatwg/html issues. Help appreciated.
As the meeting date in the subject is tentative, please indicate alternatives if that day/time does not work for you. I'm fairly flexible except for Wednesdays.
Kind regards,
Anne