Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(524)

Issue 356243003: Block mixed <picture> and <img srcset> by default. (Closed)

Created:
6 years, 5 months ago by Mike West
Modified:
6 years, 5 months ago
CC:
blink-reviews, gavinp+loader_chromium.org, Nate Chapin
Project:
blink
Visibility:
Public.

Description

Block mixed <picture> and <img srcset> by default. It's going to be more or less impossible to begin blocking mixed <img> content by default, given the amount of usage we're likely to see in the wild (I'm still waiting for metrics from Chrome stable, but I'm not hopeful). I think it will be significantly less impossible to avoid the same mistake with the new responsive hotness. This CL treats <picture> and <img srcset> as active content, blocking them by default when mixed. BUG=390158 Committed: https://src.chromium.org/viewvc/blink?view=rev&revision=177385

Patch Set 1 #

Patch Set 2 : Tests. #

Messages

Total messages: 8 (0 generated)
Mike West
Hey Yoav, is this a sane implementation? I'm not going to try to land this ...
6 years, 5 months ago (2014-06-30 14:14:21 UTC) #1
Yoav Weiss
On 2014/06/30 14:14:21, Mike West wrote: > Hey Yoav, is this a sane implementation? > ...
6 years, 5 months ago (2014-06-30 15:18:25 UTC) #2
Mike West
WDYT, Tom? Is this something we should try? I think it is. :) -mike
6 years, 5 months ago (2014-07-01 12:42:22 UTC) #3
Tom Sepez
I think this aligns with the principle that new features should be secure by default. ...
6 years, 5 months ago (2014-07-01 17:20:49 UTC) #4
Mike West
On 2014/07/01 17:20:49, Tom Sepez wrote: > I think this aligns with the principle that ...
6 years, 5 months ago (2014-07-02 10:44:25 UTC) #5
Mike West
The CQ bit was checked by mkwst@chromium.org
6 years, 5 months ago (2014-07-02 10:44:28 UTC) #6
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/mkwst@chromium.org/356243003/20001
6 years, 5 months ago (2014-07-02 10:45:32 UTC) #7
commit-bot: I haz the power
6 years, 5 months ago (2014-07-02 13:31:39 UTC) #8
Message was sent while issue was closed.
Change committed as 177385

Powered by Google App Engine
This is Rietveld 408576698