window.opener is null... didn't use to be

Viewed 1275

In our software, we have a page with a link that opens a page within the same site in a new tab using target='_blank'. When the user is done working on that newly opened page, they click a button and when the page refreshes, it calls the following code.

window.opener.location.href = window.opener.location.href; window.close();

This has worked fine for ages but within the last week or so stopped working in all browsers. I can't seem to find anything when I google it about a new security restriction being implemented that would cause this. Any idea what's going on and how to get it working again? I've tested the following code in chrome, firefox, edge and IE11. In all but IE11 window.opener is null. In IE it is not. Is there possibly a new security setting in browsers that would cause this?

<html>
<body>
<a href="page2.html" target="_blank">click me</a>
</body>
</html>

<html>
<body>
<script>
alert(window.opener === null);
</script>
</body>
</html>
1 Answers

I am not sure which version of chrome browser you tested your code on. To avoid "tab-napping" attacks, many browsers have started implementing noopener behavior by default for anchors that target _blank.

Chrome enabled noopener behavior in release 88.

Safari also enabled this in release 68.

I couldn't find any reference to IE 11 change. But it's worth trying adding rel="opener" in anchor tags with target=_blank

Related