[Bug 11429] New: If allow-top-navigation is set, can the content navigate to a javascript url to run scripts in the parent domain?

http://www.w3.org/Bugs/Public/show_bug.cgi?id=11429

           Summary: If allow-top-navigation is set, can the content
                    navigate to a javascript url to run scripts in the
                    parent domain?
           Product: HTML WG
           Version: unspecified
          Platform: Other
               URL: http://www.whatwg.org/specs/web-apps/current-work/#the
                    -iframe-element
        OS/Version: other
            Status: NEW
          Severity: normal
          Priority: P3
         Component: HTML5 spec (editor: Ian Hickson)
        AssignedTo: ian@hixie.ch
        ReportedBy: contributor@whatwg.org
         QAContact: public-html-bugzilla@w3.org
                CC: mike@w3.org, public-html-wg-issue-tracking@w3.org,
                    public-html@w3.org


Specification:
http://www.whatwg.org/specs/web-apps/current-work/multipage/the-iframe-element.html
Section: http://www.whatwg.org/specs/web-apps/current-work/#the-iframe-element

Comment:
If allow-top-navigation is set, can the content navigate to a javascript url
to run scripts in the parent domain?

Posted from: 131.107.0.116

-- 
Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug.

Received on Monday, 29 November 2010 22:52:32 UTC