[Bug 14502] Why do we want to taint on style set and not on style use?

http://www.w3.org/Bugs/Public/show_bug.cgi?id=14502

--- Comment #12 from Boris Zbarsky <bzbarsky@mit.edu> 2011-10-29 01:49:13 UTC ---
I agree, esp on the "security vulnerability" bit; hence the question.

To be clear, Gecko's behavior at the moment is that if the document has set
document.domain then drawing _any_ non-CORS image into the canvas taints the
canvas.  At least that's what I believe based on code inspection; I have only
proved it, not tested it.  ;)

-- 
Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug.

Received on Saturday, 29 October 2011 01:49:16 UTC