Does it actually work cross domain? That would really surprise me.
Edit: if I understand correctly this only allows the opened page to navigate the opening page; it does not allow it to do anything else to the opener. Is that correct?
Edit: if I understand correctly this only allows the opened page to navigate the opening page; it does not allow it to do anything else to the opener. Is that correct?
link.html:
<a id="link" href="opener.html" target="_blank">Click</a>
opener.html: <script>window.opener.document.getElementById("link").href = "https://google.com";</script>
and sure enough the link was changed. If this works cross-domain, this is kind of a big deal, isn't it?It's a fairly big deal, but not much is being done about it on the browser side of things. It can only really be used for phishing style attacks.
I assumed we were still talking about window.opener.location (which can be modified across domains)