How we built it

Treat file:// URLs as having unique origin

Similar to sandboxed iframes and data: URLs, treat file:// URLs as having unique origin.

Comments

There will be some visible side effects when opening documents via a file:// URL. For example - a file:// URL will no longer be able to XHR itself - two subframes navigated to the same file:// URL will no longer be able to script each other synchronously. The rationale behind this proposal is that using a filename as the security principal can be dangerous. There is no guarantee from an OS filesystem that a given filename always points to a unique object.

Specification

Established standard

Status in Chromium

Enabled by default (launch bug) in:

  • Chrome for desktop release 45
  • Chrome for Android release 45
  • Android WebView release 45
  • Opera release 32
  • Opera for Android release 32

Consensus & Standardization

  • No public signals
  • No public signals
  • No public signals
  • No signals

Owners

Last updated on 2017-01-04