"Allowed to navigate" algorithm in whatwg

Viewed 70

I'am trying to realize when browser will throw an error due with allowed to navigate algorithm. Unfortunately, I don't understand its complex conditions.

A browsing context A is allowed to navigate a second browsing context B if the following algorithm returns true:

  1. If A is not the same browsing context as B, and A is not one of the ancestor browsing contexts of B, and B is not a top-level browsing context, and A's active document's active sandboxing flag set has its sandboxed navigation browsing context flag set, then return false.

  2. Otherwise, if B is a top-level browsing context, and is one of the ancestor browsing contexts of A, then:

    1. If A's active window has transient activation and A's active document's active sandboxing flag set has its sandboxed top-level navigation with user activation browsing context flag set, then return false.

    2. Otherwise, if A's active window does not have transient activation and A's active document's active sandboxing flag set has its sandboxed top-level navigation without user activation browsing context flag set, then return false.

  3. Otherwise, if B is a top-level browsing context, and is neither A nor one of the ancestor browsing contexts of A, and A's Document's active sandboxing flag set has its sandboxed navigation browsing context flag set, and A is not the one permitted sandboxed navigator of B, then return false.

  4. Return true.

If anybody knows how to present and show every condition with understanable language, I would be glad. Also if it possible - could you express this with js code

1 Answers

The first thing you need to understand is the concept of a browsing context. A tab, window, frame or iframe that presents a document to the user is a browsing context.

When a user opens a tab in their browser and accesses a URL from your origin through the address bar, this creates a top-level browsing context.

If your document uses framesets or iframes these each create a child browsing context whose parent is the top-level context previously mentioned. The parent can be accessed through means such as iframe.contentWindow or window.parent.

Each child can also be a parent to it's own child contexts. The top-level context of every descendant will be the original tab that was opened and can be accessed through window.top.

Sandboxing is automatically applied to a top level context. Only descendants of this context can interact with it. Sandboxing can also be applied to descendant contexts through a Content Security Policy. Siblings or ancestors cannot access a sandboxed context. If a descendant context belongs to a different origin than it's parent, an exception must be made to the Same Origin Policy to allow access between them.

If your document opens a new tab or window, this creates a new top-level context with a single exception to it's sandbox. The opener context becomes the one permitted sandboxed navigator. Normally two top-level contexts cannot interact with each other, but in this case the opener can control new context that it created. The opened context can also access the one that created it through window.opener.

In addition to these restricitions. Sandboxing can also be applied to a context if it has been opened programatically and not interacted with. This is known as transient activation.

So, with all of that in mind. The Allowed to Navigate algorithm essentially boils down to this sequence :

If :

  • A and B are not part of the same frameset, and
  • B is not a descendant of A, and
  • B is a not top-level context, and
  • A is sandboxed, then
  • Navigation is not allowed

Else, if :

  • B is a top-level context, and
  • A is descended from B , and
  • A has been not interacted with, or
  • Access to A is denied by CSP, then
  • Navigation is not allowed

Else, if :

  • B is a top-level context, and
  • B is not A, and
  • A is not descended from B, and
  • A is sandboxed, and
  • A did not open B, then
  • Navigation is not allowed

Else :

  • Navigation is allowed
Related