[whatwg] Please disallow "javascript:" URLs in browser address bars

Nikita Popov privat at ni-po.com
Sat Jul 24 04:26:22 PDT 2010


On 24.07.2010 02:33, Bjartur Thorlacius wrote:
>
> Wrong.  Plain wrong. Kids who like to test stuff do things like this. I
> do agree though that the urlbar isn't the right place, there should be
> a different prompt for this kind of stuff.  Probably disabled at compile
> time by default and accessible by recompile (or addon).
>    
Not everybody who executes JavaScript Code using the address bar is a 
Linux freak who knows how to compile a browser. This mustn't be a 
hard-accessible configuration option.

I really don't like the idea of disallowing it totally. It should 
suffice to prompt the user whether he is sure he want's to execute the 
script.



More information about the whatwg mailing list