> So, the story so far is that the spec has added something it labels "semi-trusted events" - that is an event triggered from a trusted event of a whitelisted type. The precedence here is popup blocking - browsers already have rules for which events are "more trusted than others" in terms of likely expressing user intent. (An example makes this clearer: scripts are typically allowed to call from a click event listener, but are typically not allowed to call from an load or mouseover listener.)

Those rules are part of a standard these days:

You might want to file a bug to extend the list of trusted event types there.


