ISSUE-180: Add "allow-popups" for iframe@sandbox

allowpopups

Add "allow-popups" for iframe@sandbox

State:
CLOSED
Product:
HTML 5 spec
Raised by:
Adrian Bateman
Opened on:
2011-10-03
Description:
This issue was raised on behalf of Jacob Rossi, based on the following bug: http://www.w3.org/Bugs/Public/show_bug.cgi?id=12393

----

There's currently no way for a sandboxed iframe to generate popups (which for
some mashup scenarios, may be valid). We should add an "allow-popups" token for
the sandbox attribute.

When set, window.open(), showModalDialog() [1], and links with target=”_blank”
would be allowed. However, the newly created browsing contexts should inherit
the sandbox restrictions of the context from which the popup was created.

Here's one good use case:

A site sandboxes a maps widget. The maps widget offers options to launch a
popup for a larger map or for finding directions.

By default in both Chrome and IE10, the popups are blocked. Using allow-popups
enables the control to work as expected while still sandboxing the widget in
the other ways.

[1] http://www.w3.org/Bugs/Public/show_bug.cgi?id=12391
Related Actions Items:
No related actions
Related emails:
  1. RE: Spec changes for ISSUE-180 change proposal (from ian@hixie.ch on 2012-04-03)
  2. RE: CfC: Publish ten heartbeat drafts as WDs (from Paul.Cotton@microsoft.com on 2012-03-29)
  3. RE: Spec changes for ISSUE-180 change proposal (from Jacob.Rossi@microsoft.com on 2012-03-29)
  4. RE: CfC: Publish ten heartbeat drafts as WDs (from Paul.Cotton@microsoft.com on 2012-03-27)
  5. Re: Spec changes for ISSUE-180 change proposal (from ian@hixie.ch on 2012-03-26)
  6. Re: CfC: Publish ten heartbeat drafts as WDs (from rubys@intertwingly.net on 2012-03-22)
  7. Re: {minutes} HTML WG telecon 2012-03-22 (from glenn@skynav.com on 2012-03-22)
  8. {minutes} HTML WG telecon 2012-03-22 (from glenn@skynav.com on 2012-03-22)
  9. Spec changes for ISSUE-180 change proposal (was {minutes} HTML WG telecon 2012-03-08: issue progress, heartbeat drafts, other topics) (from Jacob.Rossi@microsoft.com on 2012-03-16)
  10. RE: {minutes} HTML WG telecon 2012-03-08: issue progress, heartbeat drafts, other topics (from Jacob.Rossi@microsoft.com on 2012-03-16)
  11. {minutes} HTML WG telecon 2012-01-26: issue progress, task force reports, other business (from eoconnor@apple.com on 2012-01-26)
  12. Re: {agenda} HTML WG telecon 2012-01-26: issue progress, task force reports, other business (from janina@rednote.net on 2012-01-25)
  13. {agenda} HTML WG telecon 2012-01-26: issue progress, task force reports, other business (from Paul.Cotton@microsoft.com on 2012-01-25)
  14. RE: Close ISSUE-180: allowpopups by Amicable Resolution (from Paul.Cotton@microsoft.com on 2012-01-25)
  15. HTML WG Minutes (Re: {agenda} HTML WG telecon 2012-01-19: issue progress, other business) (from glenn@skynav.com on 2012-01-19)
  16. Re: {agenda} HTML WG telecon 2012-01-19: issue progress, other business (from janina@rednote.net on 2012-01-18)
  17. {agenda} HTML WG telecon 2012-01-19: issue progress, other business (from rubys@intertwingly.net on 2012-01-18)
  18. HTML WG minutes (Re: {agenda} HTML WG telecon 2012-01-12: issue progress, other business) (from mjs@apple.com on 2012-01-12)
  19. {agenda} HTML WG telecon 2012-01-12: issue progress, other business (from mjs@apple.com on 2012-01-12)
  20. CfC: Close ISSUE-180: allowpopups by Amicable Resolution (from mjs@apple.com on 2012-01-11)
  21. {minutes} HTML WG telecon 2011-12-15: issue progress, editor's drafts, speech xg (from eoconnor@apple.com on 2011-12-15)
  22. Re: HTML-ISSUE-180 (allowpopups): Add 'allow-popups' for iframe@sandbox [HTML 5 spec] (from rubys@intertwingly.net on 2011-12-15)
  23. Re: HTML-ISSUE-180 (allowpopups): Add 'allow-popups' for iframe@sandbox [HTML 5 spec] (from ian@hixie.ch on 2011-12-14)
  24. {agenda} HTML WG telecon 2011-12-15: issue progress, editor's drafts, speech xg (from mjs@apple.com on 2011-12-14)
  25. RE: {minutes} HTML WG telecon 2011-12-08: actions, issues and task force reports (from adrianba@microsoft.com on 2011-12-08)
  26. {agenda} HTML WG telecon 2011-12-08: actions, issues and task force reports (from Paul.Cotton@microsoft.com on 2011-12-07)
  27. {minutes} HTML WG telecon 2011-12-01: actions and issues (from eoconnor@apple.com on 2011-12-01)
  28. {agenda} HTML WG telecon 2011-12-01: actions and issues (from Paul.Cotton@microsoft.com on 2011-11-29)
  29. {minutes} HTML WG telecon 2010-10-20: action and issue updates (from rubys@intertwingly.net on 2011-11-10)
  30. {agenda} HTML WG telecon 2010-10-20: action and issue updates (from mjs@apple.com on 2011-11-09)
  31. ISSUE-180 allowpopups: Chairs Solicit Alternate Proposals or Counter-Proposals (from mjs@apple.com on 2011-11-09)
  32. minutes for HTML WG f2f, 2011-11-04, part 1 (from mike@w3.org on 2011-11-05)
  33. RE: {minutes} HTML WG telecon 2010-10-27: issue updates, task force reports (from adrianba@microsoft.com on 2011-10-27)
  34. {agenda} HTML WG telecon 2010-10-27: issue updates, task force reports (from Paul.Cotton@microsoft.com on 2011-10-26)
  35. {minutes} HTML WG telecon 2011-10-06: Action items, new issues, issue progress, revert request, WG F2F registration (from rubys@intertwingly.net on 2011-10-06)
  36. {agenda} HTML WG telecon 2011-10-06: Action items, new issues, issue progress, revert request, WG F2F registration (from Paul.Cotton@microsoft.com on 2011-10-05)
  37. Issue 180: allowpopups - Chairs Solicit Proposals (from rubys@intertwingly.net on 2011-10-04)
  38. Re: HTML-ISSUE-180 (allowpopups): Add 'allow-popups' for iframe@sandbox [HTML 5 spec] (from Jacob.Rossi@microsoft.com on 2011-10-04)
  39. Re: HTML-ISSUE-180 (allowpopups): Add 'allow-popups' for iframe@sandbox [HTML 5 spec] (from ian@hixie.ch on 2011-10-03)
  40. HTML-ISSUE-180 (allowpopups): Add 'allow-popups' for iframe@sandbox [HTML 5 spec] (from sysbot+tracker@w3.org on 2011-10-03)

Related notes:

http://html5.org/tools/web-apps-tracker?from=7055&to=7056

Sam Ruby, 20 Apr 2012, 15:33:24

Display change log ATOM feed


Maciej Stachowiak <mjs@apple.com>, Sam Ruby <rubys@intertwingly.net>, Chairs, Michael[tm] Smith <mike@w3.org>, Staff Contact
Tracker: documentation, (configuration for this group), originally developed by Dean Jackson, is developed and maintained by the Systems Team <w3t-sys@w3.org>.
$Id: 180.html,v 1.1 2019/10/11 08:02:40 carcone Exp $