data protocol: was RE: [xsl] node-setting() escaped text

Subject: data protocol: was RE: [xsl] node-setting() escaped text
From: "bryan" <bry@xxxxxxxxxx>
Date: Thu, 13 Feb 2003 15:21:37 +0100
>data:text/html,<b>hello</b>
>into netscape's location bar)

why do I think this is a security problem? Hmm 
data:text/html,<b>hello</b><br/><p
onclick="javascript:window.open('http://www.xml.com')">hello</p>

anyway it's interesting that it wasn't done as an app, asynchronous
pluggable protocol, if it were then one could launch mozilla from within
IE by calling the protocol, on the other hand as it wasn't this opens
the way up for an ie implementation. In fact it wouldn't be difficult at
all, of course as ie has enough security bugs...



 XSL-List info and archive:  http://www.mulberrytech.com/xsl/xsl-list


Current Thread