[tor-bugs] #16300 [Tor Browser]: Make sure the BroadcastChannel API adheres to our URL bar domain isolation
Tor Bug Tracker & Wiki
blackhole at torproject.org
Fri Jun 5 16:48:34 UTC 2015
#16300: Make sure the BroadcastChannel API adheres to our URL bar domain isolation
---------------------------------------+--------------------------
Reporter: gk | Owner: tbb-team
Type: task | Status: new
Priority: major | Milestone:
Component: Tor Browser | Version:
Keywords: ff38-esr, tbb-linkability | Actual Points:
Parent ID: | Points:
---------------------------------------+--------------------------
The BroadcastChannel API allows cross-site communication within the same
origin. We have a stronger notion of "same origin": the same URL bar
domain. Thus, we must restrain this API to make it adhere to our URL bar
isolation scheme.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16300>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list