Re: [css-color][filter-effects] (was: Re: [filter-effects] Tainted filter primitives)

On Sat, Dec 14, 2013 at 8:11 AM, Tab Atkins Jr. <jackalmage@gmail.com>wrote:

> That's silly.  There's no reason to break currentcolor just because
> :visited is being used.  Plus, depending on implementation strategy,
> actually getting the sanitized color is expensive (as you have to
> rerun style matching, excluding all rules with :visited in their
> selectors).
>

FWIW, it's essential that getting the sanitized value be exactly as
expensive as getting the regular value. Otherwise you open yourself to
timing attacks.

Rob
-- 
Jtehsauts  tshaei dS,o n" Wohfy  Mdaon  yhoaus  eanuttehrotraiitny  eovni
le atrhtohu gthot sf oirng iyvoeu rs ihnesa.r"t sS?o  Whhei csha iids  teoa
stiheer :p atroa lsyazye,d  'mYaonu,r  "sGients  uapr,e  tfaokreg iyvoeunr,
'm aotr  atnod  sgaoy ,h o'mGee.t"  uTph eann dt hwea lmka'n?  gBoutt  uIp
waanndt  wyeonut  thoo mken.o w

Received on Friday, 13 December 2013 21:48:38 UTC