<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>5398</bug_id>
          
          <creation_ts>2005-10-16 22:08:13 -0700</creation_ts>
          <short_desc>source visible when &lt;script&gt; used inside &lt;option&gt;</short_desc>
          <delta_ts>2005-11-07 14:30:04 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Forms</component>
          <version>420+</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.4</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Antti Koivisto">koivisto</reporter>
          <assigned_to name="Adele Peterson">adele</assigned_to>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>22146</commentid>
    <comment_count>0</comment_count>
    <who name="Antti Koivisto">koivisto</who>
    <bug_when>2005-10-16 22:08:13 -0700</bug_when>
    <thetext>When &lt;script&gt; is used inside &lt;option&gt; the script source (along with the result) is visible in the rendered 
select list.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22147</commentid>
    <comment_count>1</comment_count>
      <attachid>4375</attachid>
    <who name="Antti Koivisto">koivisto</who>
    <bug_when>2005-10-16 22:11:25 -0700</bug_when>
    <thetext>Created attachment 4375
test case

Gecko/IE show this correctly, tested with TOT</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22187</commentid>
    <comment_count>2</comment_count>
      <attachid>4393</attachid>
    <who name="Antti Koivisto">koivisto</who>
    <bug_when>2005-10-17 20:01:56 -0700</bug_when>
    <thetext>Created attachment 4393
patch

The problem is that the DTD does not allow &lt;script&gt; as a child of &lt;option&gt;.
Insertion fails in the parser but the text content gets inserted anyway,
becoming visible. This patch adds script as a legal child element for option
and changes HTMLOptionElementImpl::text() method to ignore the script content.
This seems to match Gecko&apos;s behaviour.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22189</commentid>
    <comment_count>3</comment_count>
      <attachid>4393</attachid>
    <who name="Dave Hyatt">hyatt</who>
    <bug_when>2005-10-17 20:37:06 -0700</bug_when>
    <thetext>Comment on attachment 4393
patch

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22219</commentid>
    <comment_count>4</comment_count>
      <attachid>4393</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2005-10-18 09:52:33 -0700</bug_when>
    <thetext>Comment on attachment 4393
patch

Needs to use traverseNextSibling(this), rather than nextSibling(). Otherwise we
could get stuck if there&apos;s something in there with a child that&apos;s a script tag
(in theory).

Also, what about &lt;style&gt; tags?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22222</commentid>
    <comment_count>5</comment_count>
    <who name="Antti Koivisto">koivisto</who>
    <bug_when>2005-10-18 10:41:51 -0700</bug_when>
    <thetext>(In reply to comment #4)
&gt; (From update of attachment 4393 [edit])
&gt; Needs to use traverseNextSibling(this), rather than nextSibling(). Otherwise we
&gt; could get stuck if there&apos;s something in there with a child that&apos;s a script tag
&gt; (in theory).

True (in theory).

&gt; Also, what about &lt;style&gt; tags?

What about them?
</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22876</commentid>
    <comment_count>6</comment_count>
      <attachid>4467</attachid>
    <who name="Antti Koivisto">koivisto</who>
    <bug_when>2005-10-24 22:48:26 -0700</bug_when>
    <thetext>Created attachment 4467
updated patch

use traverseNextSibling(this) instead of nextSibling()
I still don&apos;t get the comment about &lt;style&gt; tags</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22877</commentid>
    <comment_count>7</comment_count>
    <who name="Dave Hyatt">hyatt</who>
    <bug_when>2005-10-24 22:51:38 -0700</bug_when>
    <thetext>&lt;style&gt; tags aren&apos;t relevant here, since they should in theory be found to be illegal and moved to the 
head.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22913</commentid>
    <comment_count>8</comment_count>
      <attachid>4467</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2005-10-25 08:18:56 -0700</bug_when>
    <thetext>Comment on attachment 4467
updated patch

Looks fine, r=me.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>22920</commentid>
    <comment_count>9</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2005-10-25 09:02:29 -0700</bug_when>
    <thetext>Somehow I missed the part about changing the DTD to allow &lt;script&gt; inside &lt;select&gt;. Clearly there&apos;s no 
issue with &lt;style&gt;. Looks like we&apos;re ready to go here.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>23799</commentid>
    <comment_count>10</comment_count>
    <who name="Adele Peterson">adele</who>
    <bug_when>2005-11-07 14:30:04 -0800</bug_when>
    <thetext>I committed this change.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>4375</attachid>
            <date>2005-10-16 22:11:25 -0700</date>
            <delta_ts>2005-10-16 22:11:25 -0700</delta_ts>
            <desc>test case</desc>
            <filename>option-script.html</filename>
            <type>text/html</type>
            <size>93</size>
            <attacher name="Antti Koivisto">koivisto</attacher>
            
              <data encoding="base64">PGh0bWw+Cjxib2R5Pgo8c2VsZWN0Pgo8b3B0aW9uPgo8c2NyaXB0PmRvY3VtZW50LndyaXRlKCdz
dHVmZicpPC9zY3JpcHQ+Cjwvc2VsZWN0Pgo8L2J1dHRvbj4K
</data>

          </attachment>
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>4393</attachid>
            <date>2005-10-17 20:01:56 -0700</date>
            <delta_ts>2005-10-24 22:48:26 -0700</delta_ts>
            <desc>patch</desc>
            <filename>option-script.patch</filename>
            <type>text/plain</type>
            <size>1646</size>
            <attacher name="Antti Koivisto">koivisto</attacher>
            
              <data encoding="base64">SW5kZXg6IGh0bWxfZm9ybWltcGwuY3BwCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KUkNTIGZpbGU6IC9jdnMvcm9vdC9X
ZWJDb3JlL2todG1sL2h0bWwvaHRtbF9mb3JtaW1wbC5jcHAsdgpyZXRyaWV2aW5nIHJldmlzaW9u
IDEuMTk4CmRpZmYgLXAgLXUgLXIxLjE5OCBodG1sX2Zvcm1pbXBsLmNwcAotLS0gaHRtbF9mb3Jt
aW1wbC5jcHAJOSBPY3QgMjAwNSAwMzozMTowOSAtMDAwMAkxLjE5OAorKysgaHRtbF9mb3JtaW1w
bC5jcHAJMTggT2N0IDIwMDUgMDI6NTM6MzQgLTAwMDAKQEAgLTM0MzYsMTAgKzM0MzYsMTUgQEAg
RE9NU3RyaW5nIEhUTUxPcHRpb25FbGVtZW50SW1wbDo6dGV4dCgpIAogICAgICAgICAgICAgcmV0
dXJuIHRleHQ7CiAgICAgfQogCi0gICAgY29uc3QgTm9kZUltcGwgKm4gPSB0aGlzOwotICAgIHdo
aWxlICgobiA9IG4tPnRyYXZlcnNlTmV4dE5vZGUodGhpcykpKSB7CisgICAgY29uc3QgTm9kZUlt
cGwgKm4gPSB0aGlzLT5maXJzdENoaWxkKCk7CisgICAgd2hpbGUgKG4pIHsKICAgICAgICAgaWYg
KG4tPm5vZGVUeXBlKCkgPT0gTm9kZTo6VEVYVF9OT0RFIHx8IG4tPm5vZGVUeXBlKCkgPT0gTm9k
ZTo6Q0RBVEFfU0VDVElPTl9OT0RFKQogICAgICAgICAgICAgdGV4dCArPSBuLT5ub2RlVmFsdWUo
KTsKKyAgICAgICAgLy8gc2tpcCBzY3JpcHQgY29udGVudAorICAgICAgICBpZiAobi0+aXNFbGVt
ZW50Tm9kZSgpICYmIG4tPmhhc1RhZ05hbWUoSFRNTE5hbWVzOjpzY3JpcHRUYWcpKQorICAgICAg
ICAgICAgbiA9IG4tPm5leHRTaWJsaW5nKCk7CisgICAgICAgIGVsc2UKKyAgICAgICAgICAgIG4g
PSBuLT50cmF2ZXJzZU5leHROb2RlKHRoaXMpOwogICAgIH0KIAogICAgIHJldHVybiB0ZXh0OwpJ
bmRleDogaHRtbF9mb3JtaW1wbC5oCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KUkNTIGZpbGU6IC9jdnMvcm9vdC9XZWJD
b3JlL2todG1sL2h0bWwvaHRtbF9mb3JtaW1wbC5oLHYKcmV0cmlldmluZyByZXZpc2lvbiAxLjkw
CmRpZmYgLXAgLXUgLXIxLjkwIGh0bWxfZm9ybWltcGwuaAotLS0gaHRtbF9mb3JtaW1wbC5oCTI4
IFNlcCAyMDA1IDIyOjAxOjM2IC0wMDAwCTEuOTAKKysrIGh0bWxfZm9ybWltcGwuaAkxOCBPY3Qg
MjAwNSAwMjo1MzozNSAtMDAwMApAQCAtNjg2LDcgKzY4Niw3IEBAIHB1YmxpYzoKIAogICAgIHZp
cnR1YWwgSFRNTFRhZ1N0YXR1cyBlbmRUYWdSZXF1aXJlbWVudCgpIGNvbnN0IHsgcmV0dXJuIFRh
Z1N0YXR1c09wdGlvbmFsOyB9CiAgICAgdmlydHVhbCBpbnQgdGFnUHJpb3JpdHkoKSBjb25zdCB7
IHJldHVybiAyOyB9Ci0gICAgdmlydHVhbCBib29sIGNoZWNrRFREKGNvbnN0IE5vZGVJbXBsKiBu
ZXdDaGlsZCkgeyByZXR1cm4gbmV3Q2hpbGQtPmlzVGV4dE5vZGUoKTsgfQorICAgIHZpcnR1YWwg
Ym9vbCBjaGVja0RURChjb25zdCBOb2RlSW1wbCogbmV3Q2hpbGQpIHsgcmV0dXJuIG5ld0NoaWxk
LT5pc1RleHROb2RlKCkgfHwgbmV3Q2hpbGQtPmhhc1RhZ05hbWUoSFRNTE5hbWVzOjpzY3JpcHRU
YWcpOyB9CiAKICAgICB2aXJ0dWFsIGJvb2wgaXNGb2N1c2FibGUoKSBjb25zdDsKIAo=
</data>
<flag name="review"
          id="752"
          type_id="1"
          status="-"
          setter="darin"
    />
          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>4467</attachid>
            <date>2005-10-24 22:48:26 -0700</date>
            <delta_ts>2005-10-25 08:18:56 -0700</delta_ts>
            <desc>updated patch</desc>
            <filename>option-script2.patch</filename>
            <type>text/plain</type>
            <size>1698</size>
            <attacher name="Antti Koivisto">koivisto</attacher>
            
              <data encoding="base64">SW5kZXg6IGh0bWwvaHRtbF9mb3JtaW1wbC5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQpSQ1MgZmlsZTogL2N2cy9y
b290L1dlYkNvcmUva2h0bWwvaHRtbC9odG1sX2Zvcm1pbXBsLmNwcCx2CnJldHJpZXZpbmcgcmV2
aXNpb24gMS4xOTgKZGlmZiAtcCAtdSAtcjEuMTk4IGh0bWwvaHRtbF9mb3JtaW1wbC5jcHAKLS0t
IGh0bWwvaHRtbF9mb3JtaW1wbC5jcHAJOSBPY3QgMjAwNSAwMzozMTowOSAtMDAwMAkxLjE5OAor
KysgaHRtbC9odG1sX2Zvcm1pbXBsLmNwcAkyNSBPY3QgMjAwNSAwNTo0Nzo0NyAtMDAwMApAQCAt
MzQzNiwxMCArMzQzNiwxNSBAQCBET01TdHJpbmcgSFRNTE9wdGlvbkVsZW1lbnRJbXBsOjp0ZXh0
KCkgCiAgICAgICAgICAgICByZXR1cm4gdGV4dDsKICAgICB9CiAKLSAgICBjb25zdCBOb2RlSW1w
bCAqbiA9IHRoaXM7Ci0gICAgd2hpbGUgKChuID0gbi0+dHJhdmVyc2VOZXh0Tm9kZSh0aGlzKSkp
IHsKKyAgICBjb25zdCBOb2RlSW1wbCAqbiA9IHRoaXMtPmZpcnN0Q2hpbGQoKTsKKyAgICB3aGls
ZSAobikgewogICAgICAgICBpZiAobi0+bm9kZVR5cGUoKSA9PSBOb2RlOjpURVhUX05PREUgfHwg
bi0+bm9kZVR5cGUoKSA9PSBOb2RlOjpDREFUQV9TRUNUSU9OX05PREUpCiAgICAgICAgICAgICB0
ZXh0ICs9IG4tPm5vZGVWYWx1ZSgpOworICAgICAgICAvLyBza2lwIHNjcmlwdCBjb250ZW50Cisg
ICAgICAgIGlmIChuLT5pc0VsZW1lbnROb2RlKCkgJiYgbi0+aGFzVGFnTmFtZShIVE1MTmFtZXM6
OnNjcmlwdFRhZykpCisgICAgICAgICAgICBuID0gbi0+dHJhdmVyc2VOZXh0U2libGluZyh0aGlz
KTsKKyAgICAgICAgZWxzZQorICAgICAgICAgICAgbiA9IG4tPnRyYXZlcnNlTmV4dE5vZGUodGhp
cyk7CiAgICAgfQogCiAgICAgcmV0dXJuIHRleHQ7CkluZGV4OiBodG1sL2h0bWxfZm9ybWltcGwu
aAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09ClJDUyBmaWxlOiAvY3ZzL3Jvb3QvV2ViQ29yZS9raHRtbC9odG1sL2h0bWxf
Zm9ybWltcGwuaCx2CnJldHJpZXZpbmcgcmV2aXNpb24gMS45MApkaWZmIC1wIC11IC1yMS45MCBo
dG1sL2h0bWxfZm9ybWltcGwuaAotLS0gaHRtbC9odG1sX2Zvcm1pbXBsLmgJMjggU2VwIDIwMDUg
MjI6MDE6MzYgLTAwMDAJMS45MAorKysgaHRtbC9odG1sX2Zvcm1pbXBsLmgJMjUgT2N0IDIwMDUg
MDU6NDc6NDggLTAwMDAKQEAgLTY4Niw3ICs2ODYsNyBAQCBwdWJsaWM6CiAKICAgICB2aXJ0dWFs
IEhUTUxUYWdTdGF0dXMgZW5kVGFnUmVxdWlyZW1lbnQoKSBjb25zdCB7IHJldHVybiBUYWdTdGF0
dXNPcHRpb25hbDsgfQogICAgIHZpcnR1YWwgaW50IHRhZ1ByaW9yaXR5KCkgY29uc3QgeyByZXR1
cm4gMjsgfQotICAgIHZpcnR1YWwgYm9vbCBjaGVja0RURChjb25zdCBOb2RlSW1wbCogbmV3Q2hp
bGQpIHsgcmV0dXJuIG5ld0NoaWxkLT5pc1RleHROb2RlKCk7IH0KKyAgICB2aXJ0dWFsIGJvb2wg
Y2hlY2tEVEQoY29uc3QgTm9kZUltcGwqIG5ld0NoaWxkKSB7IHJldHVybiBuZXdDaGlsZC0+aXNU
ZXh0Tm9kZSgpIHx8IG5ld0NoaWxkLT5oYXNUYWdOYW1lKEhUTUxOYW1lczo6c2NyaXB0VGFnKTsg
fQogCiAgICAgdmlydHVhbCBib29sIGlzRm9jdXNhYmxlKCkgY29uc3Q7CiAK
</data>
<flag name="review"
          id="775"
          type_id="1"
          status="+"
          setter="darin"
    />
          </attachment>
      

    </bug>

</bugzilla>