Charles McCathieNevile wrote: >> ... it exposes users to a potential security risk, and there's nothing >> the user can do about it except disabling scripting. I think that is a >> problem. > > SURE. That doesn't make it a bug per se. It also exposes the user to a > bunch of functionality that they might appreciate. I thnk it's a > decision to implement or not that way, and to use a user agent that does > that or not. I would be surprised if desktop browsers for general > release were so permissive. All major desktop browsers allow form.submit() to happen with no user confirmation. And form.submit() is _very_ commonly used. -BorisReceived on Thursday, 8 June 2006 15:10:25 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 8 January 2008 14:18:55 GMT