document-policy
document-policy copied to clipboard
Feature proposal: Disable named access on `window`
While for quick hacks the named access on window behavior is a feature, in more complex applications this behavior introduces subtle bugs that are hard to detect. Could maybe Document Policy save us, asks Paul Irish?
Any security issues arising from this are known as “DOM clobbering”: https://portswigger.net/web-security/dom-based/dom-clobbering