[Webkit-unassigned] [Bug 131033] Security Policy error when using MathML in canvas

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Apr 1 05:25:03 PDT 2016


https://bugs.webkit.org/show_bug.cgi?id=131033

Frédéric Wang (:fredw) <fred.wang at free.fr> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
         Depends on|                            |85733

--- Comment #7 from Frédéric Wang (:fredw) <fred.wang at free.fr> ---
SVGImage has changed in bug 119639. There is a new comment suggesting that foreignObject could be allowed in SVG image in the future, but I can't find the corresponding bug (and bug 119639 is not public).

> // FIXME: Once foreignObject elements within SVG images are updated to not leak cross-origin data
> // (e.g., visited links, spellcheck) we can remove the SVGForeignObjectElement check here and
> // research if we can remove the Image::hasSingleSecurityOrigin mechanism entirely.

I'll probably go back to this once the patch for MathML href lands.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.webkit.org/pipermail/webkit-unassigned/attachments/20160401/07eb90d6/attachment.html>


More information about the webkit-unassigned mailing list