Last Comment Bug 180771 - Controllers and commanddispatchers are scary, same with focusedElement and focusedWindow, maybe something else
: Controllers and commanddispatchers are scary, same with focusedElement and fo...
Status: RESOLVED FIXED
[adt2][sg:investigation]
:
Product: Core
Classification: Components
Component: XUL (show other bugs)
: Trunk
: x86 Windows 2000
: P3 normal (vote)
: ---
Assigned To: Christopher Aillon (sabbatical, not receiving bugmail)
:
Mentors:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2002-11-18 11:14 PST by bsharma
Modified: 2012-02-24 11:35 PST (History)
7 users (show)
See Also:
Crash Signature:
(edit)
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments

Description bsharma 2002-11-18 11:14:32 PST
This bug is reported as the issue in the module review and jrgm asked me to make
a bug out of it.

 - make these accessible from chrome only.
Comment 1 jag (Peter Annema) 2003-03-28 16:08:54 PST
Shouldn't be hard to fix.
Comment 2 Johnny Stenback (:jst, jst@mozilla.com) 2003-04-01 15:14:17 PST
Do these need to be scriptable *on* non-chrome windows? If so, we'll need to
check that we're accessed from chrome in the getters for these (by calling
IsCallerChrome() in GlobalWindowImpl), if not, we can move these attributes into
nsIDOMChromeWindow.idl.
Comment 3 Rafael Ebron (:rebron) 2003-04-04 14:19:23 PST
navtriage:marking need info.  Mitch, can you comment on this bug for Buffy?

thx.
Comment 4 Mitchell Stoltz (not reading bugmail) 2003-04-07 14:43:53 PDT
Jag, what's the security risk here?
Comment 5 jag (Peter Annema) 2003-04-11 15:24:18 PDT
I think the focusedWindow and focusedElement attributes are the only ones that
might (need to test) give someone access to chrome from non-chrome. The rest
should be okay, and we probably want to provide them to XUL authors.

You can also access the commandDispatcher from nsIControllers, not sure if we
really need it on there.
Comment 6 Samir Gehani 2003-05-05 16:38:05 PDT
adt: nsbeta1+/adt2
Comment 7 Heikki Toivonen (remove -bugzilla when emailing directly) 2003-05-29 14:50:38 PDT
Chris will try to get this for 1.4final, reassigning.
Comment 8 Daniel Veditz [:dveditz] 2012-02-24 11:35:36 PST
per comment 0 these are chrome only for sure now.

Note You need to log in before you can comment on or make changes to this bug.