Set Cross-Origin-Opener-Policy: same-origin on all pages #5442
+64
−4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hello Team,
This PR fixes HackerOne Report 2681420. In the previous fix #4910, @segiddins add the header to all standard pages (not errors). However, the fix did not cover the cases of non-existing paths (errors). This PR fixes the issue by ensuring all pages, even errors, have the header correctly set. I tested this locally, and it should work fine on all paths. Can you kindly review and merge this PR and then close the H1 report so that I can claim the bounty?
Best,
Ali