2 ms·
It's too complicated. The complexity in the code leads to more opportunities for bugs and exploits and more maintenance cost. Also it breaks the isolation model
by slowenough 7y ago
It's too complicated. The complexity in the code leads to more opportunities for bugs and exploits and more maintenance cost. Also it breaks the isolation model since you can do all sorts of crazy exploits just with HTML and CSS (animation event listeners for XSS etc).
I investigated this path after PoCing the original (you can see the code in a directory plugins/appminifier and public/voodoo/src/plugins/appminifer, I think) but there's all sorts of interaction issues that arise when you attempt to filter the HTML in this way.
Efficient in terms of what? Bandwidth, from a certain point of view but you lose the "source of absolute truth" that a screenshot is, and at the cost of interaction quirks. Also, not necessarily CPU efficient, as you have to do a lot of bookkeeping to transmit events to the right places and keep the local tree in sync with the remote tree.
The main reason I avoided it was the security holes introduced by breaking the strict isolation model of pixels, and the complexity.
You're welcome to fork and improve on the work begun in appminifier! If you go down that path, just know, there be dragons, and good luck!