Last Comment Bug 180771 - Controllers and commanddispatchers are scary, same with focusedElement and focusedWindow, maybe something else
: Controllers and commanddispatchers are scary, same with focusedElement and fo...
Product: Core
Classification: Components
Component: XUL (show other bugs)
: Trunk
: x86 Windows 2000
P3 normal (vote)
: ---
Assigned To: Christopher Aillon (sabbatical, not receiving bugmail)
: Neil Deakin
Depends on:
  Show dependency treegraph
Reported: 2002-11-18 11:14 PST by bsharma
Modified: 2012-02-24 11:35 PST (History)
7 users (show)
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Description User image bsharma 2002-11-18 11:14:32 PST
This bug is reported as the issue in the module review and jrgm asked me to make
a bug out of it.

 - make these accessible from chrome only.
Comment 1 User image jag (Peter Annema) 2003-03-28 16:08:54 PST
Shouldn't be hard to fix.
Comment 2 User image Johnny Stenback (:jst, 2003-04-01 15:14:17 PST
Do these need to be scriptable *on* non-chrome windows? If so, we'll need to
check that we're accessed from chrome in the getters for these (by calling
IsCallerChrome() in GlobalWindowImpl), if not, we can move these attributes into
Comment 3 User image Rafael Ebron (:rebron) 2003-04-04 14:19:23 PST
navtriage:marking need info.  Mitch, can you comment on this bug for Buffy?

Comment 4 User image Mitchell Stoltz (not reading bugmail) 2003-04-07 14:43:53 PDT
Jag, what's the security risk here?
Comment 5 User image jag (Peter Annema) 2003-04-11 15:24:18 PDT
I think the focusedWindow and focusedElement attributes are the only ones that
might (need to test) give someone access to chrome from non-chrome. The rest
should be okay, and we probably want to provide them to XUL authors.

You can also access the commandDispatcher from nsIControllers, not sure if we
really need it on there.
Comment 6 User image Samir Gehani 2003-05-05 16:38:05 PDT
adt: nsbeta1+/adt2
Comment 7 User image Heikki Toivonen (remove -bugzilla when emailing directly) 2003-05-29 14:50:38 PDT
Chris will try to get this for 1.4final, reassigning.
Comment 8 User image Daniel Veditz [:dveditz] 2012-02-24 11:35:36 PST
per comment 0 these are chrome only for sure now.

Note You need to log in before you can comment on or make changes to this bug.