W3C home > Mailing lists > Public > www-svg@w3.org > October 2010

preventing SVG script from running

From: Jennifer Yu <Jennifer.Yu@microsoft.com>
Date: Wed, 20 Oct 2010 22:59:23 +0000
To: "www-svg@w3.org" <www-svg@w3.org>
Message-ID: <48243DDF6137E64487EBE3D73E68027714494AA1@TK5EX14MBXC130.redmond.corp.microsoft.com>
Hi SVG Working Group,

If I have a server that hosts SVG, is there any way to prevent another website from executing script embedded within the SVG on my server?

The description of the HTML <img> tag allows a web author to prevent externally-hosted SVG from executing script. I did not, however, find mention of a way to prevent an external site from executing script within SVG hosted on my server. If I want to treat SVG like another image format and allow users to upload SVG images to my server, is there currently any way to prevent script inside the uploaded SVG from executing?

Thanks,
Jen
Received on Wednesday, 20 October 2010 23:01:06 GMT

This archive was generated by hypermail 2.3.1 : Friday, 8 March 2013 15:54:46 GMT