Re: [whatwg/webidl] Can we change promise resolution behaviour to reduce security issues (Issue #1584)

mgaudet left a comment (whatwg/webidl#1584)

An update here: There's an experimental implementation in Firefox Nightly available if anyone would like to try it out. Set preference `dom.promise.experimental_safe_resolve` 

The specification text is approximately correct at this point: https://tc39.es/proposal-thenable-curtailment/

I'll be proposing this for stage 2.7 at the next TC39 meeting hopefully.

In terms of things which could be improved: The [previously linked streams change](https://github.com/whatwg/streams/pull/1326) could be partially reverted as it would be protecting against a state change which becomes impossible, 

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/webidl/issues/1584#issuecomment-4718095547
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/webidl/issues/1584/4718095547@github.com>

Received on Tuesday, 16 June 2026 11:10:39 UTC