vulns.co
/
GKData.io MCP

WHATWG · 1 min read

HTML COOP: opener separation and same-origin authority

Defines how opener policies affect browsing-context separation during navigation. The standard expressly distinguishes severing an opener relationship from a robust boundary between same-origin documents: storage, service workers, messaging and server responses can preserve shared authority.

Open the reference Technical StandardReviewed 2026-10-03

How to use this reference

Model window references separately from origin-wide data and service authority. For an owned application, document every shared client capability and server data path before relying on opener separation; combine appropriate embedding, cookie and response controls with an explicit trust-domain design.

Before reading

  • Browser origin and navigation concepts
  • HTTP session and response-cache fundamentals

Context and limits

  • A specification defines intended behavior; this review does not establish per-value support in deployed browsers.
  • Opener separation alone does not partition origin-wide storage or grant application-level authorization.
  • This resource complements message validation and request-context resources by modeling the isolation boundary itself.

Sources and provenance

  1. HTML Standard: Cross-origin opener policies WHATWG · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software