3 ms·
It's absolutely not a reasonable thing to define and target. The bottom line is the feature is a FEATURE and will continue to exist, so trying to police how far
by ArchReaper 7y ago
It's absolutely not a reasonable thing to define and target. The bottom line is the feature is a FEATURE and will continue to exist, so trying to police how far websites take it is ultimately a non-starter.
Browser vendors could hypothetically start adding specific types of exceptions to make certain types of the 'hidden box' trick not work, but that would ultimately mean those website developers simply switch to whatever method works. The problem isn't solved, it's just re-coded.
TLDR: There is NO SOLUTION, because there is NO PROBLEM. The feature works as intended, as written in the spec.
- chrismorgan 7y agoBe careful: just because a feature is working as intended and specified, doesn’t mean that there’s no problem. The spec can be just bad. (I say this as a matter of how you express such things, not about this particular case. I agree with you in considering there to be no bug here, but rather that this is a serious feature that shouldn’t be messed with—and pretty fundamentally can’t without unravelling substantial foundations of the web platform.)
- nine_k 7y agoThink about the reasons why e.g. CORS was invented and implemented, despite XHR requests across domains being a perfectly working feature.