[Django] #37394: System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-popups

4 views
Skip to first unread message

Django

unread,
Oct 3, 2026, 2:48:16 PM (5 days ago) Oct 3
to django-...@googlegroups.com
#37394: System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-
popups
-------------------------------------+-------------------------------------
Reporter: venkatchalla06 | Type: Bug
Status: new | Component: Core
| (System checks)
Version: dev | Severity: Normal
Keywords: | Triage Stage:
| Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-------------------------------------+-------------------------------------
`check_cross_origin_opener_policy` (in
`django/core/checks/security/base.py`) validates
`SECURE_CROSS_ORIGIN_OPENER_POLICY` against
`CROSS_ORIGIN_OPENER_POLICY_VALUES`, which currently lists only `same-
origin`, `same-origin-allow-popups`, and `unsafe-none`, and raises
`security.E024` (an Error) for any other value.

The HTML standard defines a fourth `Cross-Origin-Opener-Policy` value,
`noopener-allow-popups`, supported by Chrome and Safari. It severs the
opener relationship even for same-origin popups, providing stronger
isolation than `same-origin-allow-popups`.

Because the value is missing from the allow-list, a project that sets the
valid, more-hardened `SECURE_CROSS_ORIGIN_OPENER_POLICY = "noopener-allow-
popups"` fails `manage.py check --deploy` with `security.E024`, even
though `SecurityMiddleware` emits the header correctly at runtime.

Proposed fix: add `"noopener-allow-popups"` to
`CROSS_ORIGIN_OPENER_POLICY_VALUES`. A patch with a test and docs
(versionadded 6.2) is ready.

Reference: https://html.spec.whatwg.org/multipage/browsers.html#cross-
origin-opener-policies
--
Ticket URL: <https://code.djangoproject.com/ticket/37394>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

Django

unread,
Oct 4, 2026, 12:01:27 PM (4 days ago) Oct 4
to django-...@googlegroups.com
#37394: System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-
popups
-------------------------------------+-------------------------------------
Reporter: venkatchalla06 | Owner: Farhan
| Ali
Type: Bug | Status: assigned
Component: Core (System | Version: dev
checks) |
Severity: Normal | Resolution:
Keywords: | Triage Stage:
| Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-------------------------------------+-------------------------------------
Changes (by Farhan Ali):

* owner: (none) => Farhan Ali
* status: new => assigned

--
Ticket URL: <https://code.djangoproject.com/ticket/37394#comment:1>

Django

unread,
Oct 6, 2026, 7:07:05 AM (2 days ago) Oct 6
to django-...@googlegroups.com
#37394: System check rejects valid Cross-Origin-Opener-Policy value noopener-allow-
popups
-------------------------------------+-------------------------------------
Reporter: venkatchalla06 | Owner: Farhan
| Ali
Type: New feature | Status: assigned
Component: Core (System | Version: dev
checks) |
Severity: Normal | Resolution:
Keywords: | Triage Stage: Accepted
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-------------------------------------+-------------------------------------
Changes (by Sarah Boyce):

* cc: Rob Hudson (added)
* stage: Unreviewed => Accepted
* type: Bug => New feature

Comment:

I'll treat this as a new feature to add support here rather than a bug as
I don't think noopener-allow-popups was available when Django's CSP
feature was implemented
I agree it sounds wrong for Django to reject a valid value. Rob, please
shout if there is a reason we should disallow it
--
Ticket URL: <https://code.djangoproject.com/ticket/37394#comment:2>
Reply all
Reply to author
Forward
0 new messages