- From: <bugzilla@jessica.w3.org>
- Date: Sat, 29 Oct 2011 01:49:14 +0000
- To: public-html-bugzilla@w3.org
http://www.w3.org/Bugs/Public/show_bug.cgi?id=14502 --- Comment #12 from Boris Zbarsky <bzbarsky@mit.edu> 2011-10-29 01:49:13 UTC --- I agree, esp on the "security vulnerability" bit; hence the question. To be clear, Gecko's behavior at the moment is that if the document has set document.domain then drawing _any_ non-CORS image into the canvas taints the canvas. At least that's what I believe based on code inspection; I have only proved it, not tested it. ;) -- Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are the QA contact for the bug.
Received on Saturday, 29 October 2011 01:49:16 UTC