Summary: | For WebKit plug-ins, beforeload can be called recursively (esp. with AdBlock style extensions) | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Alexey Proskuryakov <ap> | ||||||
Component: | Plug-ins | Assignee: | Alexey Proskuryakov <ap> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | mitz, simon.fraser | ||||||
Priority: | P2 | Keywords: | InRadar | ||||||
Version: | 528+ (Nightly build) | ||||||||
Hardware: | All | ||||||||
OS: | All | ||||||||
Bug Depends on: | |||||||||
Bug Blocks: | 74340 | ||||||||
Attachments: |
|
Description
Alexey Proskuryakov
2010-10-12 11:54:47 PDT
Created attachment 70554 [details]
proposed patch
Comment on attachment 70554 [details] proposed patch View in context: https://bugs.webkit.org/attachment.cgi?id=70554&action=review > WebCore/html/HTMLPlugInElement.cpp:108 > + if (m_inBeforeLoadEventHandler) { > + // The plug-in hasn't loaded yet, and it makes no sense to try to load if beforeload handler happened to touch the plug-in element. > + // That would recursively call beforeload for the same element. > + return false; > + } This should return 0, not return false. Committed <http://trac.webkit.org/changeset/69596>. |