W3C home > Mailing lists > Public > whatwg@whatwg.org > May 2008

[whatwg] Online whitelist problem

From: Anders Carlsson <andersca@apple.com>
Date: Wed, 28 May 2008 17:45:26 -0700
Message-ID: <2AA1A5DA-8055-44FC-89A4-93AEEC1C600E@apple.com>
Hi,

one problem with the online whitelist in cache manifest files is that  
it matches on whole URLs only.

This makes embedding for example Google Maps into a web app difficult,  
since you want to allow urls like

http://maps.google.com/maps/vp?spn=0.040888,0.085831&z=13&key=ABQIAAAAzr2EBOXUKnm_jVnk0OJI7xSosDVG8KKPE1-m51RBrvYughuyMxQ-i1QfUnH94QxWIa6N4U6MouMmBA&vp=37.4419,-122.1419
http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAzr2EBOXUKnm_jVnk0OJI7xSosDVG8KKPE1-m51RBrvYughuyMxQ-i1QfUnH94QxWIa6N4U6MouMmBA
http://mt0.google.com/mt?n=404&v=ap.74&hl=sv&x=1316&y=3176&zoom=4&s=Gali
http://mt1.google.com/mt?n=404&v=ap.74&hl=sv&x=1315&y=3175&zoom=4&s=
http://mt1.google.com/mt?n=404&v=ap.74&hl=sv&x=1315&y=3177&zoom=4&s=Ga
http://mt2.google.com/mt?n=404&v=ap.74&hl=sv&x=1316&y=3175&zoom=4&s=Gal
http://mt2.google.com/mt?n=404&v=ap.74&hl=sv&x=1316&y=3177&zoom=4&s=Galil
http://mt3.google.com/mt?n=404&v=ap.74&hl=sv&x=1315&y=3176&zoom=4&s=G

and it's especially a problem since you don't know beforehand what  
URLs to allow.

Maybe the whitelist needs to be extended to do host matching or maybe  
we need another solution.

Anders

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.whatwg.org/pipermail/whatwg-whatwg.org/attachments/20080528/7b841671/attachment.htm>
Received on Wednesday, 28 May 2008 17:45:26 UTC

This archive was generated by hypermail 2.4.0 : Wednesday, 22 January 2020 16:59:02 UTC