[whatwg] Spec for location object needs to make some properties unforgeable; need supporting WebIDL changes

Ian Hickson ian at hixie.ch
Mon Nov 19 17:40:58 PST 2012


On Tue, 25 Sep 2012, Boris Zbarsky wrote:
>
> Turns out, some things care about at least the .href and .toString of 
> Location objects for security-check purposes.  So they need to be 
> unforgeable.  But of course WebIDL doesn't provide a way to make 
> anything other than readonly attributes unforgeable.  It seems like it 
> needs to.

I'm going to assume heycam is going to add an interface-level 
[Unforgeable] annotation that does this.

   https://www.w3.org/Bugs/Public/show_bug.cgi?id=20008

I've updated HTML accordingly.

-- 
Ian Hickson               U+1047E                )\._.,--....,'``.    fL
http://ln.hixie.ch/       U+263A                /,   _.. \   _\  ;`._ ,.
Things that are impossible just take longer.   `._.-(,_..'--(,_..'`-.;.'


More information about the whatwg mailing list