2.25 Ensure 'Allow file or directory picker APIs to be called without prior user gesture' Is Disabled

Information

This setting controls the ability for showOpenFilePicker(), showSaveFilePicker(), and showDirectoryPicker() web APIs to be called without user interaction.

If the value for FileOrDirectoryPickerWithoutGestureAllowedForOrigins is not changed from the default, it will behave as if it is disabled.

Rationale:

Setting this policy would allow the URLs selected to call the showOpenFilePicker(), showSaveFilePicker(), and showDirectoryPicker() web APIs without any user gesture/interaction. This policy does not need to be set for this reason.

Impact:

Disabling this policy should have no impact on the user.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Allow file or directory picker APIs to be called without prior user gesture

Default Value:

Unset (Disabled)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|9.4

Plugin: Windows

Control ID: ef72e0fd11e1a0fa85368ed6ba9f2c5f463d83eca583af801978a2c6df2b8c76