[Bug 21203] EME leaks information cross-origin

https://www.w3.org/Bugs/Public/show_bug.cgi?id=21203

David Dorwin <ddorwin@google.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|REOPENED                    |RESOLVED
         Resolution|---                         |FIXED

--- Comment #27 from David Dorwin <ddorwin@google.com> ---
I made the change in comment #23 in
https://dvcs.w3.org/hg/html-media/rev/5369218d899b.

(In reply to Joe Steele from comment #26)
> I would also change step 2. of the procedure to say that the CDM provides
> the defaultURL based on the initData and leave it at that. Since the
> initData is CDM specific that is about all you can say.

initData is container-specific, though the traditional use for CENC has been
protection system-specific.

I changed the text in https://dvcs.w3.org/hg/html-media/rev/9060ac54fe3d to be
more generic while still implying that the defaultURL should come from the
initData. I also removed the potential interpretation that the defaultURL not
needs to be explicitly for the specific keySystem.

-- 
You are receiving this mail because:
You are the QA Contact for the bug.

Received on Monday, 28 October 2013 20:14:57 UTC