Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

Disable data URLs in top-level navigation #2424

Open
jumde opened this issue Mar 24, 2020 · 4 comments · May be fixed by #2419
Open

Disable data URLs in top-level navigation #2424

jumde opened this issue Mar 24, 2020 · 4 comments · May be fixed by #2419

Comments

@jumde
Copy link
Contributor

jumde commented Mar 24, 2020

Description:

Data URLs should not be allowed in top-level navigation

Steps to Reproduce

  1. Navigate to jumde.github.io/test/data1.html
  2. Click Hello

Actual result:
Should not navigate to a data URL

Expected result:
Navigates to a data URL

Reproduces how often: [Easily reproduced, Intermittent Issue]
Easily

@jumde jumde added the security label Mar 24, 2020
@Brandon-T Brandon-T linked a pull request Mar 24, 2020 that will close this issue
7 tasks
@jumde
Copy link
Contributor Author

jumde commented Mar 24, 2020

@jumde
Copy link
Contributor Author

jumde commented Mar 24, 2020

We'll be using the same exceptions specified in the blog.

@iccub
Copy link
Collaborator

iccub commented Mar 30, 2020

Bumping to 1.16 for now since this requires more work and thought, if we will be able to fit it into 1.15.1 I will change the milestone back

@iccub iccub modified the milestones: 1.15.1, 1.16 Mar 30, 2020
@garvankeeley
Copy link

@jhreis jhreis added this to To do in Master List via automation Apr 10, 2020
@jhreis jhreis removed this from the 1.16 milestone Apr 22, 2020
@diracdeltas diracdeltas added the priority/P3 The next thing for us to work on. label Oct 27, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
Master List
  
To do
Development

Successfully merging a pull request may close this issue.

6 participants