New issue
Advanced search Search tips

Issue 662607 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 518038
Owner: ----
Closed: Nov 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Same origin policy prevents datauri in CSS filter url() from loading

Reported by jnied...@redhat.com, Nov 5 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:49.0) Gecko/20100101 Firefox/49.0

Steps to reproduce the problem:
1. Use a css filter 'url()' (https://www.w3.org/TR/filter-effects/#typedef-url) in combination with datauri

What is the expected behavior?
datauri filter is applied

What went wrong?
filter was not applied. Console showed:

css_filter_url_same_origin.html:1 Unsafe attempt to load URL data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zd…4IHR5cGU9InNhdHVyYXRlIiB2YWx1ZXM9IjAiLz48L2ZpbHRlcj48L3N2Zz4%3D#desaturate from frame with URL file:///home/jakub/Desktop/css_filter_url_same_origin.html. 'file:' URLs are treated as unique security origins.

css_filter_url_same_origin.html:1 Unsafe attempt to load URL data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A//www.w3.org/2000/svg%22%3E%3…%3D%22saturate%22%20values%3D%220%22/%3E%3C/filter%3E%3C/svg%3E#desaturate from frame with URL file:///home/jakub/Desktop/css_filter_url_same_origin.html. 'file:' URLs are treated as unique security origins.

Did this work before? N/A 

Does this work in other browsers? Yes

Chrome version: Version 54.0.2840.90 (64-bit)  Channel: stable
OS Version: Fedora 24
Flash Version: 

I works ok in Firefox 49.0.

One click reproduction: http://jsbin.com/razelinahi/edit?html,output
 
css_filter_url_same_origin.html
744 bytes View Download
Components: -Blink>CSS Blink>SecurityFeature

Comment 2 by f...@opera.com, Nov 7 2016

Mergedinto: 518038
Status: Duplicate (was: Unconfirmed)

Sign in to add a comment