[whatwg] Proposal to extend registerProtocolHandler

Robert O'Callahan robert at ocallahan.org
Wed Jul 6 17:53:42 PDT 2011


On Thu, Jul 7, 2011 at 12:53 PM, Robert O'Callahan <robert at ocallahan.org>wrote:

> On Thu, Jul 7, 2011 at 6:41 AM, Olli Pettay <Olli.Pettay at helsinki.fi>wrote:
>
>> On 07/06/2011 07:51 AM, Robert O'Callahan wrote:
>>
>>> I don't think browsers need to prompt for registerProtocolHandler.
>>> Instead,
>>> I would simply allow any site to register as a protocol handler for
>>> almost
>>> anything, and remember all such registration
>>>
>>
>> So all the ad sites (which are embedded via iframe or something) would
>> just register all the possible protocols so that some user might
>> accidentally use their site for protocol handling - especially if the site
>> was the first one to register the protocol.
>> Doesn't sound too good.
>>
>
> I think you could sequester the new app options sufficiently that that
> would not be worth doing.
>

You could also just deny all registerProtocolHandler() attempts from
non-toplevel frames.

Rob
-- 
"If we claim to be without sin, we deceive ourselves and the truth is not in
us. If we confess our sins, he is faithful and just and will forgive us our
sins and purify us from all unrighteousness. If we claim we have not sinned,
we make him out to be a liar and his word is not in us." [1 John 1:8-10]



More information about the whatwg mailing list