Michael
Thu Feb 17 19:40:36 CST 2005
>> Is there a
>> security issue for window.opener in HTA environment.
>
> <snip src="MSDN">
> ...an unsafe frame or iframe receives neither a referrer nor an
> opener URL from the parent HTA. This means frame or iframe is not
> affected by the parent window of the containing HTA.
> </snip>
>
And any window opened from an HTA via window.open falls into that same
category...
A option for the OP is to use showModal/ModelessDialog windows, but with
caution. Dialog windows are trusted by default from an HTA and have the
same level of local machine access as the parent HTA, so it would be unwise
to cross domains, especially to external internet domains.
--
Michael Harris
Microsoft MVP Scripting
http://maps.google.com/maps?q=Sammamish%20WA%20US