[whatwg/webidl] Use SafePromiseResolve to replace the promise resolution steps (PR #1645)

<!--
Thank you for contributing to the Web IDL Standard! Please describe the change you are making and complete the checklist below if your change is not editorial.

When you submit this PR, and each time you edit this comment (including checking a checkbox through the UI!), PR Preview will run and update it. As such make any edits in one go and only after PR Preview has run.

If you think your PR is ready to land, please double-check that the build is passing and the checklist is complete before pinging.
-->

The goal here is to improve security of the web platform by avoiding execution of user code when WebIDL resolves a promise. This is done by using the SafePromiseResolve steps provided by the ["Thenable Curtailment" proposal](https://github.com/tc39/proposal-thenable-curtailment). 

This PR only changes the promise resolve steps; Async iteration is left alone to keep compatible with TC39's async iteration steps. 

- [ ] At least two implementers are interested (and none opposed):
   * Gecko
   * …
- [ ] [Tests](https://github.com/web-platform-tests/wpt) are written and can be reviewed and commented upon at:
   * … <!-- If these tests are tentative, link a PR to make them non-tentative. -->
- [ ] [Implementation bugs](https://github.com/whatwg/meta/blob/main/MAINTAINERS.md#handling-pull-requests) are filed:
   * Chromium: …
   * Gecko: [Bug 2077196 - Use SafePromiseResolve to resolve promises in WebIDL](https://bugzilla.mozilla.org/show_bug.cgi?id=2077196)
   * WebKit: …
   * Deno: …
   * Node.js: …
   * webidl2.js: …
   * widlparser: …
- [ ] [MDN issue](https://github.com/whatwg/meta/blob/main/MAINTAINERS.md#handling-pull-requests) is filed: …
- [ ] The top of this comment includes a [clear commit message](https://github.com/whatwg/meta/blob/main/COMMITTING.md) to use. <!-- If you created this PR from a single commit, Github copied its message. Otherwise, you need to add a commit message yourself. -->

(See [WHATWG Working Mode: Changes](https://whatwg.org/working-mode#changes) for more details.)


<!--
    This comment and the below content is programmatically generated.
    You may add a comma-separated list of anchors you'd like a
    direct link to below (e.g. #idl-serializers, #idl-sequence):

    Don't remove this comment or modify anything below this line.
    If you don't want a preview generated for this pull request,
    just replace the whole of this comment's content by "no preview"
    and remove what's below.
-->
***
<a href="https://whatpr.org/webidl/1645.html" title="Last updated on Oct 1, 2026, 3:56 PM UTC (8dd16a0)">Preview</a> | <a href="https://whatpr.org/webidl/1645/6a53497...8dd16a0.html" title="Last updated on Oct 1, 2026, 3:56 PM UTC (8dd16a0)">Diff</a>
You can view, comment on, or merge this pull request online at:

  https://github.com/whatwg/webidl/pull/1645

-- Commit Summary --

  * Use SafePromiseResolve to replace the promise resolution steps in most of WebIDL

-- File Changes --

    M index.bs (16)

-- Patch Links --

https://github.com/whatwg/webidl/pull/1645.patch
https://github.com/whatwg/webidl/pull/1645.diff

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/webidl/pull/1645
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/webidl/pull/1645@github.com>

Received on Thursday, 1 October 2026 15:58:11 UTC