Closed Bug 1623826 Opened 7 months ago Closed 3 months ago

Do not expose outerWidth/outerHeight features of window.open to web content

Categories

(Core :: DOM: Core & HTML, task, P3)

task

Tracking

()

RESOLVED FIXED
mozilla80
Tracking Status
firefox80 --- fixed

People

(Reporter: arai, Assigned: arai)

References

(Blocks 1 open bug)

Details

(Keywords: dev-doc-complete, site-compat)

Attachments

(1 file, 1 obsolete file)

outerWidth/outerHeight features of window.open are supported only on Firefox.
it's better not exposing this to web content.
and if it's not used by chrome-priv code, they can be removed.

Assignee: nobody → arai.unmht
Status: NEW → ASSIGNED
Depends on: 1624150
Priority: -- → P3
Keywords: site-compat
Blocks: 1627109
Summary: Do not expose outerWidth/outerHeight features of window.open to web content → Add telemetry for non-standard outerWidth/outerHeight features of window.open

sorry, never mind.

Summary: Add telemetry for non-standard outerWidth/outerHeight features of window.open → Do not expose outerWidth/outerHeight features of window.open to web content
No longer blocks: 1627109

WINDOW_OPEN_OUTER_SIZE looks promising: after 3 days: < 0.01% (55/612.28K)

Keywords: dev-doc-needed
channel used total ratio date
nightly 79 187 2.12M 0.01% 2020/06/01 - 2020/06/10
nightly 78 1.08k 8.52M 0.01% 2020/05/04 - 2020/06/01
nightly 77 965 6.79M 0.01% 2020/04/14 - 2020/05/04
beta 78 3.9k 33.75M 0.01% 2020/06/01 - 2020/06/05
beta 77 21.01k 154.59M 0.01% 2020/05/04 - 2020/05/28

I'll remove the prove and also hide those features from window.open

Attachment #9134863 - Attachment is obsolete: true
Flags: needinfo?(arai.unmht)
Pushed by arai_a@mac.com:
https://hg.mozilla.org/integration/autoland/rev/2acb78b73c26
Do not expose outerWidth/outerHeight features of window.open to web content. r=smaug
Flags: needinfo?(arai.unmht)
Pushed by arai_a@mac.com:
https://hg.mozilla.org/integration/autoland/rev/4e76e9b8d9e5
Do not expose outerWidth/outerHeight features of window.open to web content. r=smaug
Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla80

MDN documentation updated:

Let me know if you think this needs anything else. Thanks!

Also updated the documentation for window.open

Ah great, thank you!

You need to log in before you can comment on or make changes to this bug.