4 ms·
I think the article gets this wrong. `window.crypto` should be read-only
by tixzdk 10y ago
I think the article gets this wrong. `window.crypto` should be read-only
- ifelsehow 10y agoI find the following in Chrome: > window.crypto.getRandomValues // getRandomValues() { [native code] } > window.crypto.getRandomValues = function () { return "aloha" } > window.crypto.getRandomValues() // "aloha" Not sure if this is the case in all browsers. `window.crypto` certainly should be read-only.
- niftich 10y agoIn Chrome, window.crypto is read-only: > window.crypto < Crypto {subtle: SubtleCrypto} > window.crypto = "hi!" < "hi!" > window.crypto < Crypto {subtle: SubtleCrypto} But not anything underneath, including getRandomValues(), as you write. A recent issue about this [1] on the WebCrypto spec itself was closed with 'wontfix' because in their view, polyfilling web APIs is a common and accepted practice. [1] https://github.com/w3c/webcrypto/issues/107 https://github.com/w3c/webcrypto/issues/107
- flukus 10y agoShouldn't all pollyfills check only override the functions if they're missing?
- jsjohnst 10y agoWhat if it's present but the implementation is incomplete?
- paulddraper 10y agoE.g. an extra optional parameter.
- rmrfrmrf 10y agohttps://www.w3.org/Bugs/Public/show_bug.cgi?id=25345 https://www.w3.org/Bugs/Public/show_bug.cgi?id=25345 It looks like they intentionally don't do that in order to prevent the illusion of security.