您在此处:
通过跨来源打开器策略 (COOP) 保护 Visualforce 页面
帮助保护自定义 Visualforce 页面免受外部攻击。在启用跨来源打开器策略 (COOP) 时,每个顶级自定义 Visualforce 页面将在新浏览上下文组中打开。此过程阻止其他浏览器选项卡和 Visualforce 页面与页面内容之间的直接访问。
帮助保护自定义 Visualforce 页面免受外部攻击。在启用跨来源打开器策略 (COOP) 时,每个顶级自定义 Visualforce 页面将在新浏览上下文组中打开。此过程阻止其他浏览器选项卡和 Visualforce 页面与页面内容之间的直接访问。
| 适用于 Salesforce Classic 和 Lightning Experience |
| 适用于:Contact Manager、Group、Professional、Enterprise、Performance、Unlimited 和 Developer Edition |
| 所需用户权限 | |
|---|---|
| 要修改会话安全性设置: | 自定义应用程序 |
COOP 有助于屏蔽 Visualforce 页面与跨站点脚本 (XSS),即安全漏洞。借助 XSS,攻击者在合法网页或 Web 应用程序的客户端脚本中包含恶意代码。在用户访问页面或应用程序时,网页或应用程序会将恶意脚本传递到用户的浏览器。
通过 COOP,每个顶级自定义 Visualforce 页面将在新浏览上下文组中打开。在 iframe 中打开 Visualforce 页面的浏览器内容可以访问父页面。但尝试在新选项卡或弹出窗口中打开页面的进程无法访问页面,防止潜在的跨来源攻击。
浏览器访问权限检查会使用 Visualforce 页面和从页面访问的外部站点的标题。跨来源打开器策略 (COOP) 和跨来源嵌入器策略 (COEP) 标题组合确定了 Visualforce 页面和外部站点是否可交互。要了解有关 COOP 和 COEP 的更多信息,建议在 MDN Web 文档中使用以下主题:Cross-Origin-Opener-Policy 和 Cross-Origin-Embedder-Policy。

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.