Skip to main content

Cross-Origin Opener Policy

Translation โ€ข ๋ฒˆ์—ญโ€‹

HTTP Cross-Origin-Opener-Policy ์‘๋‹ต ํ—ค๋”๋Š” ์ตœ์ƒ์œ„ ๋ฌธ์„œ๊ฐ€ Cross-Origin ๋ฌธ์„œ์™€ Browsing Context๋ฅผ ๊ณต์œ ํ•˜์ง€ ์•Š๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. COOP๋Š” (์„ค๋ น ๋ฌธ์„œ๊ฐ€ ํŒ์—…์œผ๋กœ ์—ด๋ฆฌ๋”๋ผ๋„) ๋ฌธ์„œ๋ฅผ ๊ณ„์‚ฐ์ ์œผ๋กœ ๊ฒฉ๋ฆฌํ•˜์—ฌ, ๋ฌธ์„œ์˜ ์ „์—ญ ๊ฐ์ฒด(Global Object)๊ฐ€ ๋‹ค๋ฅธ ๊ณต๊ฒฉ์ž์—๊ฒŒ ๋…ธ์ถœ๋˜์ง€ ์•Š๋„๋ก ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ณต๊ฒฉ์€ XS-Leaks๋ผ๊ณ ๋„ ์•Œ๋ ค์ ธ ์žˆ์Šต๋‹ˆ๋‹ค.

๋งŒ์ผ COOP๋ฅผ ๊ฐ€์ง„ Cross Origin ๋ฌธ์„œ (๋ณดํ˜ธํ•˜๊ณ ์ž ํ•˜๋Š” ๋ฌธ์„œ, ๊ฐ€์นญ A ๋ฌธ์„œ)๊ฐ€ B ์ฐฝ(๊ณต๊ฒฉ์ž ๋ฌธ์„œ)์— ์˜ํ•ด ์ƒˆ ์ฐฝ์—์„œ ์—ด๋ ค๋„, B ์ฐฝ์€ A ์ฐฝ์— ์ ‘๊ทผ ํ˜น์€ ๋ ˆํผ๋Ÿฐ์Šค๋ฅผ ๊ฐ€์ง€์ง€ ๋ชปํ•˜๊ณ , window.opener ๊ฐ’ ๋˜ํ•œ null์ด ๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๋‹จ์ˆœํ•˜๊ฒŒ ์™ธ๋ถ€ ๋„ค๋น„๊ฒŒ์ด์…˜์„ ์ œ์–ดํ•˜๋Š” rel=noopener๋ณด๋‹ค ๋” ๋งŽ์€ ํ†ต์ œ๊ถŒ์„ ์ค๋‹ˆ๋‹ค.