W3C home > Mailing lists > Public > public-html-bugzilla@w3.org > September 2011

[Bug 12998] Some attributes are not overridable with 'var' in browsers. See http://software.hixie.ch/utilities/js/live-dom-viewer/saved/1035

From: <bugzilla@jessica.w3.org>
Date: Thu, 22 Sep 2011 14:14:54 +0000
To: public-html-bugzilla@w3.org
Message-Id: <E1R6k3C-00067P-Gi@jessica.w3.org>
http://www.w3.org/Bugs/Public/show_bug.cgi?id=12998

--- Comment #13 from Simon Pieters <simonp@opera.com> 2011-09-22 14:14:52 UTC ---
IIRC Flash uses something like

javascript:top.location.href

as part of its "origin" security checks, so 'top' should be unforgeable in
order to keep Flash security in check.

-- 
Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug.
Received on Thursday, 22 September 2011 14:15:00 UTC

This archive was generated by hypermail 2.3.1 : Wednesday, 7 January 2015 16:31:19 UTC