Skip to content

Define the "extract an origin" operation. - #892

Merged
annevk merged 3 commits into
mainfrom
mkwst/extract-an-origin
Jan 13, 2026
Merged

annevk merged 3 commits into
mainfrom
mkwst/extract-an-origin

Conversation

@mikewest

@mikewest mikewest commented Dec 4, 2025 •

Copy link
Copy Markdown
Member

whatwg/html#11846 added an Origin interface, which relies on an "extract an origin" operation to support the creation of new Origin objects via Origin.from(...). This PR defines that operation for URL objects.

Addresses a remaining portion of whatwg/html#11534.

(See WHATWG Working Mode: Changes for more details.)


Preview | Diff

whatwg/html#11846 added an `Origin` interface, which
relies on an "extract an origin" operation to support the creation of new `Origin`
objects via `Origin.from(...)`. This PR defines that operation for `URL` objects.

Addresses a remaining portion of whatwg/html#11534.
Comment thread url.bs Outdated
Comment thread url.bs

<div algorithm>
<p>Objects implementing the {{URL}} interface's <a for="platform object">extract an origin</a> steps are
to return <a>this</a>'s <a for=URL>URL</a>'s <a for=url>origin</a>. [[!HTML]]

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's a little weird that we use "this" here, but it's probably okay.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Co-authored-by: Anne van Kesteren <annevk@annevk.nl>
@annevk

annevk commented Dec 4, 2025

Copy link
Copy Markdown
Member

WPT comments:

  • You can't create new content in WPT /interfaces/. That directory is managed automatically. It should probably be tested as part of other html.idl APIs, though perhaps it can be split, but it'll have to load html.idl.
  • It seems like we don't have tests for <a> and <area> without href attributes. From a quick skim I suspect this might not be implemented correctly.

@mikewest

mikewest commented Dec 5, 2025

Copy link
Copy Markdown
Member Author

You can't create new content in WPT /interfaces/. That directory is managed automatically. It should probably be tested as part of other html.idl APIs, though perhaps it can be split, but it'll have to load html.idl.

You're right, I didn't think about this when we moved Origin into HTML. I'll fix it up once the file's updated (https://github.com/w3c/webref/blob/main/ed/idl/html.idl is up to date, but hasn't been pulled in yet...).

It seems like we don't have tests for <a> and <area> without href attributes. From a quick skim I suspect this might not be implemented correctly.

I can add those, thanks for the suggestion!

@mikewest

mikewest commented Dec 5, 2025

Copy link
Copy Markdown
Member Author

It seems like we don't have tests for <a> and <area> without href attributes. From a quick skim I suspect this might not be implemented correctly.

I can add those, thanks for the suggestion!

You were right; Chromium's implementation was returning an opaque origin rather than throwing on Origin.from(<a>). Fixing that and updating the tests in https://chromium-review.googlesource.com/c/chromium/src/+/7231346.

brave-builds pushed a commit to brave/chromium that referenced this pull request Dec 5, 2025
When extracting an origin from `<a>` and `<area>` elements without an
`href` attribute, we're currently returning an opaque `Origin`. We
should throw instead, as there's not an origin to extract from these
elements (see [1]). Thanks to @annevk for pointing this out in [2].


[1]: https://html.spec.whatwg.org/multipage/links.html#api-for-a-and-area-elements:extract-an-origin
[2]: whatwg/url#892 (comment)

Bug: 434131026
Change-Id: I136cc0ff24355e29418e060ab384938f3615a60e
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7231346
Commit-Queue: Mike West <mkwst@chromium.org>
Reviewed-by: Antonio Sartori <antoniosartori@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1554582}
chromium-wpt-export-bot pushed a commit to web-platform-tests/wpt that referenced this pull request Dec 5, 2025
When extracting an origin from `<a>` and `<area>` elements without an
`href` attribute, we're currently returning an opaque `Origin`. We
should throw instead, as there's not an origin to extract from these
elements (see [1]). Thanks to @annevk for pointing this out in [2].

[1]: https://html.spec.whatwg.org/multipage/links.html#api-for-a-and-area-elements:extract-an-origin
[2]: whatwg/url#892 (comment)

Bug: 434131026
Change-Id: I136cc0ff24355e29418e060ab384938f3615a60e
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7231346
Commit-Queue: Mike West <mkwst@chromium.org>
Reviewed-by: Antonio Sartori <antoniosartori@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1554582}
chromium-wpt-export-bot pushed a commit to web-platform-tests/wpt that referenced this pull request Dec 5, 2025
When extracting an origin from `<a>` and `<area>` elements without an
`href` attribute, we're currently returning an opaque `Origin`. We
should throw instead, as there's not an origin to extract from these
elements (see [1]). Thanks to @annevk for pointing this out in [2].

[1]: https://html.spec.whatwg.org/multipage/links.html#api-for-a-and-area-elements:extract-an-origin
[2]: whatwg/url#892 (comment)

Bug: 434131026
Change-Id: I136cc0ff24355e29418e060ab384938f3615a60e
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7231346
Commit-Queue: Mike West <mkwst@chromium.org>
Reviewed-by: Antonio Sartori <antoniosartori@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1554582}
Comment thread url.bs

<div algorithm="URL/extract an origin">
<p>Objects implementing the {{URL}} interface's <a for="platform object">extract an origin</a> steps are
to return <a>this</a>'s <a for=URL>URL</a>'s <a for=url>origin</a>. [[!HTML]]

@shannonbooth shannonbooth Dec 8, 2025 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something that I noticed is not covered by WPT (just incase this case was not considered in the design) is the below case:

let url = new URL('data:text/plain,opaque');
const origin1 = Origin.from(url);
const origin2 = Origin.from(url);
console.log(origin1.isSameOrigin(origin2));

Which from https://url.spec.whatwg.org/#concept-url-origin the result will be false:

-> Otherwise
Return a new opaque origin.

NOTE: This does indeed mean that these URLs cannot be same origin with themselves.

A similar case also happens for https://html.spec.whatwg.org/multipage/links.html#api-for-a-and-area-elements:extract-an-origin I believe.

I can make the updates to WPT, just thought I'd double check I have the right understanding, since I suppose it is possible to hold on to the origin for those objects to have different behaviour if-so desired

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, we should test that and I think it should return false indeed.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 I thought I'd added tests like that to https://wpt.fyi/results/html/browsers/origin/api/origin-comparison.any.html?label=master&label=experimental&aligned, but I didn't. If you have a PR, great! If not, I'll put one up this morning (as I need to fix the IDL test anyway).

@shannonbooth shannonbooth Dec 9, 2025 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing comprehensive so far unfortunately sorry! Only have so far the URL & hyperlink element case from hacking around my implementation locally. I haven't built up anything more comprehensive for the other cases like for WindowOrWorkerGlobal scope which seem like would be a bit different in that the ESO returns the same origin origin instance (besides from data URL workers, which create a new opaque one when callef).

@shannonbooth shannonbooth Dec 24, 2025 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay, I have been busy with day-job and other stuff lately rather than hacking on web-platform stuff like I would like to do, finally got around to raising something now web-platform-tests/wpt#56922

Edit: Unrelated question - but will this new section of the specification be linkable somehow? At least locally I can't figure out what such a link will end up being. For the HTML spec it's things like https://html.spec.whatwg.org/multipage/webappapis.html#windoworworkerglobalscope-mixin:extract-an-origin, but I only managed to find that from cross-links which doesn't work in the URL specification at a standalone document. Probably some other method of getting it I am missing though!

lando-worker Bot pushed a commit to mozilla-firefox/firefox that referenced this pull request Dec 11, 2025
…<a>` and `<area>`., a=testonly

Automatic update from web-platform-tests
[Origin API] `.from()` should throw on `<a>` and `<area>`.

When extracting an origin from `<a>` and `<area>` elements without an
`href` attribute, we're currently returning an opaque `Origin`. We
should throw instead, as there's not an origin to extract from these
elements (see [1]). Thanks to @annevk for pointing this out in [2].

[1]: https://html.spec.whatwg.org/multipage/links.html#api-for-a-and-area-elements:extract-an-origin
[2]: whatwg/url#892 (comment)

Bug: 434131026
Change-Id: I136cc0ff24355e29418e060ab384938f3615a60e
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7231346
Commit-Queue: Mike West <mkwst@chromium.org>
Reviewed-by: Antonio Sartori <antoniosartori@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1554582}

--

wpt-commits: 97bfa0053605daefab920aded71c705030ff7f39
wpt-pr: 56522
@annevk

annevk commented Jan 13, 2026

Copy link
Copy Markdown
Member

Now that the tests have landed let me merge this. There's still one outstanding issue surrounding MessageEvent and ExtendableMessageEvent but no need to block on that I think: whatwg/html#11993.

@annevk
annevk merged commit b6b3251 into main Jan 13, 2026
2 of 3 checks passed
@annevk
annevk deleted the mkwst/extract-an-origin branch January 13, 2026 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants