[whatwg] Online whitelist problem

Anders Carlsson andersca at apple.com
Wed May 28 17:45:26 PDT 2008


Hi,

one problem with the online whitelist in cache manifest files is that  
it matches on whole URLs only.

This makes embedding for example Google Maps into a web app difficult,  
since you want to allow urls like

http://maps.google.com/maps/vp?spn=0.040888,0.085831&z=13&key=ABQIAAAAzr2EBOXUKnm_jVnk0OJI7xSosDVG8KKPE1-m51RBrvYughuyMxQ-i1QfUnH94QxWIa6N4U6MouMmBA&vp=37.4419,-122.1419
http://maps.google.com/maps?file=api&v=2&key=ABQIAAAAzr2EBOXUKnm_jVnk0OJI7xSosDVG8KKPE1-m51RBrvYughuyMxQ-i1QfUnH94QxWIa6N4U6MouMmBA
http://mt0.google.com/mt?n=404&v=ap.74&hl=sv&x=1316&y=3176&zoom=4&s=Gali
http://mt1.google.com/mt?n=404&v=ap.74&hl=sv&x=1315&y=3175&zoom=4&s=
http://mt1.google.com/mt?n=404&v=ap.74&hl=sv&x=1315&y=3177&zoom=4&s=Ga
http://mt2.google.com/mt?n=404&v=ap.74&hl=sv&x=1316&y=3175&zoom=4&s=Gal
http://mt2.google.com/mt?n=404&v=ap.74&hl=sv&x=1316&y=3177&zoom=4&s=Galil
http://mt3.google.com/mt?n=404&v=ap.74&hl=sv&x=1315&y=3176&zoom=4&s=G

and it's especially a problem since you don't know beforehand what  
URLs to allow.

Maybe the whitelist needs to be extended to do host matching or maybe  
we need another solution.

Anders

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.whatwg.org/pipermail/whatwg-whatwg.org/attachments/20080528/7b841671/attachment-0001.htm>


More information about the whatwg mailing list