Feature Policy for limiting same-origin iframe document access

Two primary goals: - Be able to embed iframes that have same-origin as other frames in the frame tree but not be able to directly script them. - Have a same-origin iframe with other iframes be in a separate event loop.

Allowing cross-document DOM access has made the web very complicated. Wouldn't it be nice if individual pages could opt themselves or their frames into a simplier mode which didn't allow cross-document access?

Documentation

Specification

Editor's draft

Status in Chromium

Blink>DOM


In development (tracking bug)

Consensus & Standardization

After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.

  • No public signals
  • No public signals
  • No public signals
  • No signals

Owner

Last updated on 2019-07-29