Skip to content

Only expose iframe body size for same-origin navigations without cross-origin redirects - #1961

Open
noamr wants to merge 1 commit into
mainfrom
iframe-body-size
Open

noamr wants to merge 1 commit into
mainfrom
iframe-body-size

Conversation

@noamr

@noamr noamr commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

These values are "CORS-protected" for subresources, however iframes (and etc) are never CORS-protected, so we only expose these values for same-origin iframes without cross-origin redirects.

Closes #1960

(See WHATWG Working Mode: Changes for more details.)


Preview | Diff

These values are "CORS-protected" for subresources, however iframes
(and <object> etc) are never CORS-protected, so we only expose these
values for same-origin iframes without cross-origin redirects.

(This is already the ground truth in blink, and AFAIK webkit doesn't
 expose cross-origin body size info)

Closes #1960
@noamr noamr changed the title Don't expose body size for cross-origin or tainted subframe navigations Only expose iframe body size for same-origin navigations without cross-origin redirects Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Response body info (decoded/encoded size) should be zeroed for cross-origin subframe navigation

1 participant