New issue
Advanced search Search tips

Issue 688773 link

Starred by 3 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug



Sign in to add a comment

mismatch between "perform a security check" in html spec and blink

Project Member Reported by jochen@chromium.org, Feb 5 2017

Issue description

https://html.spec.whatwg.org/multipage/browsers.html#integration-with-idl says that for non-cross origin objects, we have to do a security check nevertheless (step 2).

This should only trigger for same origin objects that aren't same origin-domain.

Currently, we do that implicitly in V8WrapperInstantiationScope::securityCheck when creating wrappers, however, we don't do that in general (for pre-existing wrappers).
 

Comment 1 by peria@chromium.org, Mar 2 2017

Labels: Hotlist-Interop
Status: Available (was: Untriaged)

Comment 2 by sim...@opera.com, Apr 12 2017

FYI a change to the test to no longer separately test assert_throws(null, ...):
https://github.com/w3c/web-platform-tests/pull/5528
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 12 2018

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: peria@chromium.org
Status: Available (was: Untriaged)
We still don't have a good idea about how to handle this, but this is definitely an issue that we should take care of.

Sign in to add a comment