Last Comment Bug 502824 - Don't allow window.focus on *self* in response to clicks (prevent pop-unders)
: Don't allow window.focus on *self* in response to clicks (prevent pop-unders)
[fixed by bug 369306 ]
Product: Core
Classification: Components
Component: DOM (show other bugs)
: Trunk
: All All
-- enhancement with 2 votes (vote)
: mozilla2.0b7
Assigned To: Nobody; OK to take it and work on it
: Andrew Overholt [:overholt]
Depends on: 369306
Blocks: 565104 355482
  Show dependency treegraph
Reported: 2009-07-07 07:37 PDT by Jesse Ruderman
Modified: 2011-05-30 03:10 PDT (History)
11 users (show)
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Description User image Jesse Ruderman 2009-07-07 07:37:28 PDT
Clicks should allow scripts to call window.focus() on other windows, since they can open new focused windows, but should not allow scripts to call window.focus() on themselves, since that is pretty much only used to hide the origin of pop-up ads ("pop-unders").  I originally suggested this in bug 355482 comment 0.
Comment 1 User image James Darpinian 2010-02-18 21:32:15 PST
The patch in bug 369306 implements this.  Actually, the exact semantics are slightly more restrictive: window A can focus window B iff A created B.
Comment 2 User image Mike Beltzner [:beltzner, not reading bugmail] 2010-09-13 14:56:04 PDT
So does bug 369306 being fixed means this one's fixed, too?
Comment 3 User image James Darpinian 2010-09-13 16:17:33 PDT
Yes, this is fixed too.

Note You need to log in before you can comment on or make changes to this bug.