#37394: System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-
popups
-------------------------------------+-------------------------------------
Reporter: venkatchalla06 | Type: Bug
Status: new | Component: Core
| (System checks)
Version: dev | Severity: Normal
Keywords: | Triage Stage:
| Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-------------------------------------+-------------------------------------
`check_cross_origin_opener_policy` (in
`django/core/checks/security/base.py`) validates
`SECURE_CROSS_ORIGIN_OPENER_POLICY` against
`CROSS_ORIGIN_OPENER_POLICY_VALUES`, which currently lists only `same-
origin`, `same-origin-allow-popups`, and `unsafe-none`, and raises
`security.E024` (an Error) for any other value.
The HTML standard defines a fourth `Cross-Origin-Opener-Policy` value,
`noopener-allow-popups`, supported by Chrome and Safari. It severs the
opener relationship even for same-origin popups, providing stronger
isolation than `same-origin-allow-popups`.
Because the value is missing from the allow-list, a project that sets the
valid, more-hardened `SECURE_CROSS_ORIGIN_OPENER_POLICY = "noopener-allow-
popups"` fails `manage.py check --deploy` with `security.E024`, even
though `SecurityMiddleware` emits the header correctly at runtime.
Proposed fix: add `"noopener-allow-popups"` to
`CROSS_ORIGIN_OPENER_POLICY_VALUES`. A patch with a test and docs
(versionadded 6.2) is ready.
Reference:
https://html.spec.whatwg.org/multipage/browsers.html#cross-
origin-opener-policies
--
Ticket URL: <
https://code.djangoproject.com/ticket/37394>
Django <
https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.