詳細情報:
クロスオリジンオープナーポリシー (COOP) を使用した Visualforce ページの保護
外部攻撃からカスタム Visualforce ページを防御できるようにします。クロスオリジンオープナーポリシー (COOP) を有効にすると、最上位のカスタム Visualforce ページがそれぞれ新しい参照コンテキストグループで開きます。このプロセスにより、他のブラウザータブと Visualforce ページやページのコンテンツ間の直接的なアクセスが阻止されます。
外部攻撃からカスタム Visualforce ページを防御できるようにします。クロスオリジンオープナーポリシー (COOP) を有効にすると、最上位のカスタム Visualforce ページがそれぞれ新しい参照コンテキストグループで開きます。このプロセスにより、他のブラウザータブと Visualforce ページやページのコンテンツ間の直接的なアクセスが阻止されます。
| 使用可能なインターフェース: Salesforce Classic および Lightning Experience の両方 |
| 使用可能なエディション: Contact Manager Edition、Group Edition、Professional Edition、Enterprise Edition、Performance Edition、Unlimited Edition、および Developer Edition |
| 必要なユーザー権限 | |
|---|---|
| セキュリティ設定を変更する | 「アプリケーションのカスタマイズ」 |
COOP は、一種のセキュリティの脆弱性であるクロスサイトスクリプティング (XSS) から Visualforce ページを防御するのに役立ちます。攻撃者は XSS を使用して正規の Web ページまたは Web アプリケーションのクライアント側スクリプトに悪意のあるコードを含めます。ユーザーがこのページまたはアプリケーションにアクセスすると、Web ページまたはアプリケーションによって悪意のあるスクリプトがユーザーのブラウザーに配信されます。
COOP を使用すると、最上位のカスタム Visualforce ページがそれぞれ新しい参照コンテキストグループで開きます。Visualforce ページで iframe 内で開かれたブラウザーコンテンツは、親ページにアクセスできます。ただし、潜在的なクロスオリジン攻撃を阻止するために、ページを新しいタブまたはポップアップウィンドウで開こうとするプロセスはそのページにアクセスすることはできません。
ブラウザーのアクセスチェックでは、ページからアクセスする Visualforce サイトと外部サイトの両方のヘッダーが使用されます。クロスオリジンオープナーポリシー (COOP) とクロスオリジンエンベッダーポリシー (COEP) ヘッダーの組み合わせによって、Visualforce ページと外部サイトがやりとりできるかどうかが決まります。COOP および COEP についての詳細は、MDN Web ドキュメントの「Cross-Origin-Opener-Policy」および「Cross-Origin-Embedder-Policy」を参照することをお勧めします。

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.