On Wed, Apr 10, 2013 at 8:51 PM, Anne van Kesteren <annevk@annevk.nl> wrote:
> If we accept the need for a sandbox domain, same-origin loads becomes
> an option I think. And actually, even in the face of an open redirect
> you could fail flat the moment the target URL becomes cross-origin and
> not fetch it. Several APIs on the platform have a request mode of
> same-origin (different from tainted cross-origin, which will fetch)
> with an opt in availability for CORS.
>
So we need to turn all kinds of external loads into CORS same-origin loads?
That sounds like it would work, but be quite invasive to spec and implement.
Rob
--
q“qIqfq qyqoquq qlqoqvqeq qtqhqoqsqeq qwqhqoq qlqoqvqeq qyqoquq,q qwqhqaqtq
qcqrqeqdqiqtq qiqsq qtqhqaqtq qtqoq qyqoquq?q qEqvqeqnq qsqiqnqnqeqrqsq
qlqoqvqeq qtqhqoqsqeq qwqhqoq qlqoqvqeq qtqhqeqmq.q qAqnqdq qiqfq qyqoquq
qdqoq qgqoqoqdq qtqoq qtqhqoqsqeq qwqhqoq qaqrqeq qgqoqoqdq qtqoq qyqoquq,q
qwqhqaqtq qcqrqeqdqiqtq qiqsq qtqhqaqtq qtqoq qyqoquq?q qEqvqeqnq
qsqiqnqnqeqrqsq qdqoq qtqhqaqtq.q"