← Back to Baseline

MB-R285

HUMAN VERIFICATION REQUIRED ASVS 3.4.8 Cross-Origin-Opener-Policy

MB-C18 ASVS Level 3 Human Assurance Medium

All HTTP responses that initiate a document rendering (such as responses with Content-Type text/html), include the Cross-Origin-Opener-Policy header field with the same-origin directive or the same-origin-allow-popups directive as required. This prevents attacks that abuse shared access to Window objects, such as tabnabbing and frame counting.