Re: text/sandboxed-html

On Mon, Jun 14, 2010 at 4:07 PM, Joe D Williams <joedwil@earthlink.net> wrote:
>> plug-ins that don't understand sandboxing?
>
> The only way a plugin has any glimmer of "understanding 'sandboxing" is when
> the host context refuses to perform an operation requested by the
> 'sandboxed' context.

The current proposal is to communicate the sandbox state to the
plug-in via the plug-in API.

> For sandboxing to work, then the host must understand and actually implement
> the 'sandboxing' controls that the document author is requesting in a way
> that ends up delivering reasonable results in all WWW html5 browsers in
> which the UA provides the end user audience with the tools to permit a
> sandboxed context to exist.

Many plug-ins talk directly to the operating system to perform various
actions, so we need the plug-ins cooperation to make good on these
promises.

Adam

Received on Monday, 14 June 2010 23:26:16 UTC