webappsec-ISSUE-52 (unsafe DOM API): unsafe attribute requires every handler to check [UI Security]

webappsec-ISSUE-52 (unsafe DOM API): unsafe attribute requires every handler to check [UI Security]

http://www.w3.org/2011/webappsec/track/issues/52

Raised by: Brad Hill
On product: UI Security

abarth: requiring every handler to check unsafe makes it difficult to write the correct code.  better would be to be able to provide a wrapper function that filters or intercepts all unsafe events so they can be acted on wherever they are generated.

Received on Thursday, 25 April 2013 23:53:30 UTC