Files
sousa-gecko/testing/web-platform/tests/fetch/local-network-access/resources/openee.html
T
Chris Thompson 5d0c72f1ac Bug 1980184 [wpt PR 54053] - [LNA] Apply LNA only to subframe navigations, a=testonly
Automatic update from web-platform-tests
[LNA] Apply LNA only to subframe navigations

The initial implementation of LNA enforcement for subframe navigations
accidentally applies broadly to all navigations (including main frame
navigations, which are out of scope for LNA currently). This fixes the
LNA permission enforcement logic to only apply to subframe navigations,
and explicitly handle other navigation types (main frame and guest main
frame navigations are explicitly default-allowed, and fenced-frame and
prerender navigations are explicitly default-denied).

This also updates the LNA permission logic to look at the *initiator* of
the navigation rather than just the embedding frame (which may or may
not be the initiator) to align with how the ClientSecurityState for the
navigation is computed, and restricts the ability to do LNA subframe
navigations to initiators that are frame ancestors of the subframe being
navigated (so that the LNA permission prompt can only be triggered
within a single tab/window context).

As part of distinguishing different navigation types, this also updates
the LNA policy logic to have separate feature flags for configuration
each separately (particularly useful as individual kill-switches).

Bug: 428879902,409303581
Change-Id: I556c2c99f65aee6a8cdb438026ec93985b284743
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6763697
Reviewed-by: Camille Lamy <clamy@chromium.org>
Commit-Queue: Chris Thompson <cthomp@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1494172}

--

wpt-commits: 663fb6bb8b3a5fe2e99d4618d1336be7a6fa18e6
wpt-pr: 54053
2025-08-06 15:19:21 +00:00

7 lines
212 B
HTML

<!DOCTYPE html>
<meta charset="utf-8">
<title>Openee</title>
<script>
// Message back to whatever caused this page to load that it was successful.
top.opener.postMessage({ message: "loaded" }, "*");
</script>