[Webkit-unassigned] [Bug 200850] New: Put keygen element behind a runtime flag and disable it by default

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Aug 16 20:06:55 PDT 2019


https://bugs.webkit.org/show_bug.cgi?id=200850

            Bug ID: 200850
           Summary: Put keygen element behind a runtime flag and disable
                    it by default
           Product: WebKit
           Version: WebKit Nightly Build
          Hardware: Unspecified
                OS: Unspecified
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: DOM
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: rniwa at webkit.org

HTML keygen element had been removed from Chrome & Firefox in 2017, and it has been removed from the specifications.
Given the number of security bugs we've had with keygen elements, we should probably remove it altogether.

In order to gather any developer feedback regarding this element, disable keygen element by default using runtime flag.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20190817/2bdfc5bf/attachment.html>


More information about the webkit-unassigned mailing list