Closed Bug 1560741 Opened 5 years ago Closed 5 years ago

Disallow notification permission requests from cross-origin iframes

Categories

(Core :: DOM: Notifications, enhancement, P2)

enhancement

Tracking

()

RESOLVED FIXED
mozilla70
Tracking Status
firefox70 --- fixed

People

(Reporter: johannh, Assigned: ehsan.akhgari)

References

Details

(Keywords: dev-doc-complete, site-compat)

Attachments

(2 files)

To enable consistent treatment of permission requests in iframes with feature policy, we will deny requests for notification permission in cross-origin iframes.

Chrome announced the same change over 2 years ago, though strangely in my Canary they are still showing the deprecation notice.

Our Telemetry shows that usage is very low at 0.03%, so we should have little to no issues with breakage.

I am relatively confident we decided to do this without the option for the embedder to delegate the notification permission (i.e., without "Feature Policy") as it seems extremely unlikely that embedder A would want to allow embeddee B to create notifications attributed to A. (And if they were attributed to B it would violate the UX simplifications goal as we'd show B to the user whereas the goal is to almost exclusively show A.) If A wants B to create notifications attributed to A it can still do so via a custom postMessage() API.

No longer blocks: permissions-policy
Assignee: nobody → ehsan
Blocks: 1572461
Blocks: 1375683
Keywords: site-compat
Pushed by eakhgari@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/9dc1d39d2786 Part 1: Disallow notification permission requests from cross-origin iframes; r=johannh https://hg.mozilla.org/integration/autoland/rev/c08aa2078829 Part 2: Remove the now unneeded PERMISSION_REQUEST_THIRD_PARTY_ORIGIN telemetry probe; r=johannh
Flags: needinfo?(ehsan)
Pushed by eakhgari@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/b7c91018f87e Part 1: Disallow notification permission requests from cross-origin iframes; r=johannh https://hg.mozilla.org/integration/autoland/rev/efe5dc48aa87 Part 2: Remove the now unneeded PERMISSION_REQUEST_THIRD_PARTY_ORIGIN telemetry probe; r=johannh
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla70
Depends on: 1574019

I've documented this behavior on MDN; see https://github.com/mdn/sprints/issues/2464#issuecomment-564668240 for the full details.

Let me know if you've like to see any further updates; thanks!

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: