Skip to content

Restrict cross-origin nested WindowProxy access #589

Description

@wieslawsoltes

Parent: #267. Webview epic: #264.

Problem

Nested WindowProxy objects must retain stable identity across navigation while enforcing committed-origin boundaries. Cross-origin callers may use only browser-compatible safe properties/operations; direct document/runtime access must raise SecurityError, Location navigation must remain guarded, and stale or detached realm references must retire.

Implemented boundary

  • Track committed origins across nested navigation.
  • Preserve stable WindowProxy identity while switching the backing realm.
  • Expose only the supported cross-origin safe properties and operations.
  • Deny forbidden document/runtime access with SecurityError.
  • Guard cross-origin Location navigation without widening origin or resource admission.
  • Retire stale/detached realm references deterministically.
  • Add WPT-shaped/native source contracts and validation/deferred documentation.

Deferred to #267/#268

Cross-document joint session history, POST reload, bfcache, broader opener/top/parent multi-window behavior, and cumulative unchanged webview acceptance.

Validation boundary

git diff --check passed. Authored contracts were not executed under the current implementation-throughput direction.

Metadata

Metadata

Assignees

No one assigned

    Labels

    vscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions