[Webkit-unassigned] [Bug 51674] [Qt] LocalContentCanAccessRemoteUrls creates cross frame scripting vulnerability

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Jan 3 04:36:46 PST 2011


https://bugs.webkit.org/show_bug.cgi?id=51674


Benjamin Poulain <benjamin.poulain at nokia.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|UNCONFIRMED                 |NEW
           Keywords|                            |QtTriaged
           Priority|P3                          |P5
                 CC|                            |benjamin.poulain at nokia.com
     Ever Confirmed|0                           |1




--- Comment #5 from Benjamin Poulain <benjamin.poulain at nokia.com>  2011-01-03 04:36:45 PST ---
I agree with Adam, this is the intended behavior for this property.

It is very useful to do Hybrid development, in which you really want to break the security based on origin.

I agree with Alexey, the doc should be updated.

Pushparajan, could you update the doc?

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list