Skip to content

Fullscreen request on invisible document should be denied #58

Open
@upsuper

Description

@upsuper

I suppose that exposes security risks that attacker can open a background window and put it into fullscreen without having user notice it. And then when user switches window, it may start spoofing.

Metadata

Metadata

Assignees

Labels

needs concrete proposalMoving the issue forward requires someone to figure out a detailed plan

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions