Capabilities (Fugu)

Additional Windowing Controls Link copied!

Enables web applications with the window-management permission to maximize(), minimize(), and restore() their windows, and to prevent resizing through setResizable(). Additionally, new CSS media features display-state and resizable enable scripts and content to adapt to the respective window states and resizability. These features improve the usability of VDI remote application windows in Web clients, especially when it comes to titlebar window controls. The new functionality enhances existing Window Management API features: https://chromestatus.com/feature/5252960583942144

Security

Algorithm Updates in WebCrypto Link copied!

Add post-quantum cryptography and a common symmetric AEAD to the set of cryptographic algorithms available in the Web Cryptography API. This will enable developers to have access browser-provided implementations of common quantum-resistant cryptographic algorithms standardized by NIST.

  • ML-KEM - 768, 1024
  • ML-DSA - 44, 65, 87
  • ChaCha20-Poly1305
  • X-Wing

CSS

CSS Symbols() Link copied!

The CSS symbols() function lets authors define a counter style inline instead of first declaring a named @counter-style at-rule. It builds an anonymous counter style from a list of string symbols plus an optional counting system (cyclic, numeric, alphabetic, symbolic, or fixed), and is accepted as the counter style in list-style-type, the list-style shorthand, and counter() / counters().

CSS4 text-decoration-skip-spaces Link copied!

The text-decoration-skip-spaces CSS property controls whether text decoration lines (underlines, overlines, line-throughs, etc.) skip over whitespace characters. This allows authors to prevent decorations from being drawn under spaces, which is often more visually appealing.

Margin-trim Link copied!

The margin-trim CSS property may be used to omit margins before or after the first or last child of a container. This is supported on regular block containers and multicol containers.

This is somewhat similar to the effect caused by the margin quirk that is applied to P, H1, H2... elements inside BODY and table cell elements (in quirks mode), but more powerful, generic, and expressive.

Note: A previous version of the spec also applied this for flex and grid containers, but this has been removed.

Miscellaneous

Digital Credentials API (issuance support) Link copied!

This Web Platform feature enables issuing websites (e.g., a university, government agency, or bank) to securely initiate the provisioning (issuance) process of digital credentials directly into a user's mobile wallet application. On Android, this capability leverages the Android IdentityCredential CredMan system (Credential Manager). On Desktop, it leverages cross-device approaches using the CTAP protocol similar to Digital Credentials presentation.

Host and screenshot restrictions for chrome.debugger API Link copied!

The chrome.debugger extension API lets you send Chrome DevTools Prototcol commands to a specified target, for example, a tab, an iframe, or a service worker. When connecting (attaching) to a target, the API can now enforce permissions on managed browsers by validating enterprise host and screenshot policies.

On enterprise devices, some policies can restrict extensions from attaching the debugger using an all-or-nothing model at attach time (browser.debugger.attach()):

  • For hosts, the ExtensionSettings enterprise policy can be configured to block hosts for an extension, returning the error Host access is restricted by policy.
  • For screenshots, the enterprise policy DisableScreenshots enterprise policy disables screenshot capture or Data Loss Prevention (DLP) rules apply, returning the error Screenshot capture is restricted by policy.

Developers can handle attach rejections gracefully or use higher-level APIs like chrome.scripting and chrome.declarativeNetRequest that support granular origin permissions in restricted enterprise environments.

JavaScript

Multimedia

Pause media playback on not-visible iframes Link copied!

Adds a "media-playback-while-not-visible" permission policy to allow embedders to pause audible media playback of embedded iframes which are currently hidden - i.e. "display" property set to "none"; "visibility" property set to "hidden"; or zero-area (width or height equal to 0). While hidden, attempts made by the embedded iframe to render audible media will be blocked. When the frame is shown again the prohibitions should be lifted. This should allow developers to build more user-friendly experiences and to also improve the performance by letting the browser handle the playback of content that is not visible to users.

Graphics

Network / Connectivity

WebTransport Datagram writable streams and prioritization Link copied!

Adds the modern WebTransport Datagram sending API.

WebTransportDatagramDuplexStream.createWritable() creates independent WebTransportDatagramsWritable streams. Each writable has mutable sendGroup and sendOrder attributes for expressing relative priority among queued WebTransport data in the same send group. Chromium currently applies this ordering among Datagram writables.

The implementation also reports the negotiated maximum outgoing Datagram payload size and discards oversized writes as required by the WebTransport specification.

WebTransport reliability attributes Link copied!

Adds the  WebTransport.reliability  instance attribute and static WebTransport.supportsReliableOnly attribute. These APIs indicate whether the user agent supports WebTransport over exclusively reliable connections and whether an established session supports unreliable transport such as datagrams.

In Chromium, reliability initially returns "pending" and changes to  "supports-unreliable" after an HTTP/3 WebTransport connection is established.  Since Chromium does not currently support HTTP/2 fallback,  WebTransport.supportsReliableOnly returns false; any successfully established session uses HTTP/3 and supports unreliable datagrams.