8 ms·
I welcome this move, despite the possibility of some fallout from the change. It'll be painful, but even as someone who once made a living writing ActionScript
by CoreDumpling 14y ago
I welcome this move, despite the possibility of some fallout from the change. It'll be painful, but even as someone who once made a living writing ActionScript, I have to say that Flash is sufficiently annoying and insecure that it really needs to be phased out.
In the short term, this will probably cause some breakage in certain sites that try to use Flash "transparently" and "unobtrusively" for things like LSOs, drag-and-drop, clipboard access, or cross-domain XHR. These are already problematic with Flashblock installed though -- Pandora, for instance, refuses to load and there is nothing available to click-to-play since that particular Flash object is hidden.
Hopefully this will light a fire under those sites and get them to update to the appropriate HTML5 methods of doing these things (local storage, WebSockets, etc.), just like how Java applets that were used for such things have been largely phased out. Until then, however, I wouldn't be surprised if some of them simply inform you not to use Firefox to visit.
- robryan 14y agoCross domain XHR shouldn't be an issue as you only really need flash for it in IE 6 and 7.
- simonbrown 14y agoI assume you are suggesting CORS as an alternative. Unfortunately, some APIs (e.g. StackExchange) implement crossdomain.xml but not CORS.
- robryan 14y agoI was thinking of postMessage, I haven't used CORS before but it looks like it ends up giving the same kind of outcome. In my case though I control the server have have the JS on 3rd parties so it is the reverse to what you are saying.
- bad_user 14y agopostMessage is more heavyweight than CORS. Minus a couple of restrictions (i.e. with CORS you cannot rely on cookies being set, so you need to handle that from your Javascript somehow), CORS works well and it works on all major browsers, starting with IExplorer 8, which makes it awesome.
- derefr 14y agoAs an alternative, rather than requiring that all Flash shims have some sort of screen real-estate of their own to overlay a click-to-play control onto, perhaps hidden embedded Flash (or Java, or ActiveX, or whatever) objects could request the browser to prompt for their activation with an information bar.
- cheald 14y agoChrome does it somewhat unobtrusively by sticking an icon in the URL bar: http://cl.ly/3I1q3k0X0R1I2G2X1p1S http://cl.ly/3I1q3k0X0R1I2G2X1p1S Works great.
- mistercow 14y agoTo take care of the invisible Flash object problem, Firefox could copy what Chrome does for Java applets and have a bar pop up at the top of the whole page, asking if you want to allow Flash to run on the site in question.
- pdenya 14y agoIf only Chrome did this with it's current click to play implementation
- alanh 14y agoChrome has a click-to-play implementation for Flash? That is not a plugin? Do I have to go to chrome://flags or something?
- strager 14y agoYes. Preferences > Under the Hood > Privacy > Content Settings > Plug-ins > Click to play Or you can search for "Flash" or "Click to play" to find the setting.
- aeurielesn 14y agoNice. I didn't know about this until now. Nifty! Although, a bit of a elusive setting.
- deleted 14y ago[deleted]
- joejohnson 14y agoWow, thank you for sharing this. I love when Chrome obviates the need an extension to do something simple like this!
- strager 14y agoIt does, though not with the same UI as the Java plugin: http://i.imgur.com/xHrRX.png http://i.imgur.com/xHrRX.png Clicking the puzzle piece shows a menu to "always allow" or to "enable all Flash applets on this page" (and a few other things). I can see a more obtrusive/apparent UI being implemented if Firefox makes click-to-Flash default.
- felipc 14y agoFor this feature, there will also be an option to enable plugins for websites that have them hidden such as Pandora. And in addition it will be possible to whitelist/blacklist websites.
- hollerith 14y ago>already problematic with Flashblock installed though -- Pandora, for instance, refuses to load Not if you whitelist it at Tools > Add-ons > Extensions > Flashblock > Preferences.
- bad_user 14y ago... cross-domain XHR That's not a problem because Firefox has support for CORS, which is better than doing Flash because it's faster. Of course, the server must cooperate with the browser by passing back allowance headers, but that's also true for Flash, as you need the server to have a crossdomain policy file for that. Last year I wrote an article about it on my blog about how to configure it, check it out: http://bionicspirit.com/blog/2011/03/24/cross-domain-requests.html http://bionicspirit.com/blog/2011/03/24/cross-domain-request...
- masklinn 14y ago> That's not a problem because Firefox has support for CORS, which is better than doing Flash because it's faster. That's nice for a new site being developed right now, it's problematic for a site which has been stable in production for months or years and for which everybody involved in the development has moved on already.
- lysol 14y agoIf that site is the case, then lack of maintenance will have reared its ugly head long before a lack of Flash (or, the inclusion of it) broke their site.
- glanch 14y agoDon't you just love progress? Time to redo stuff that already works!
- jballanc 14y agoIsn't that the very definition of progress? I'm pretty sure the horse-and-cart worked just fine when the automobile came around.
- masklinn 14y agohorse-and-cart didn't stop working when the automobile came around. The proposal here is that we shoot all horses and burn all carts because somebody somewhere has started driving an automobile.