W3C home > Mailing lists > Public > whatwg@whatwg.org > December 2010

[whatwg] Should events be paused on detached iframes?

From: Boris Zbarsky <bzbarsky@MIT.EDU>
Date: Mon, 06 Dec 2010 19:51:53 -0500
Message-ID: <4CFD8529.6000200@mit.edu>
On 12/6/10 7:45 PM, Ian Hickson wrote:
> per spec, currently, if you grab a reference (from another Window) to a document
> that you then send into session history (bfcache), you can still mutate
> that document, call dispatchEvent() on it, run scripts in it, etc.

I don't believe Gecko would be willing to implement that, for security 
reasons.  As soon as you try to do things of that sort in a bfcached 
document it _will_ in fact get evicted.  I don't believe we plan to 
change that.  I'd be interested in what other UAs views are on this.

This is also why we drop the browsing context when an iframe is removed 
from the document.  This part we may be able to change without 
introducing security problems, maybe...  Not clear yet.

Received on Monday, 6 December 2010 16:51:53 UTC

This archive was generated by hypermail 2.4.0 : Wednesday, 22 January 2020 16:59:28 UTC