Bug 57212

Summary: script-src should block inline event handlers
Product: WebKit Reporter: Adam Barth <abarth@webkit.org>
Component: New BugsAssignee: Adam Barth <abarth@webkit.org>
Status: RESOLVED FIXED    
Severity: Normal CC: abarth@webkit.org, eric@webkit.org, webkit.review.bot@gmail.com
Priority: P2    
Version: 528+ (Nightly build)   
Hardware: Other   
OS: Mac OS X 10.5   
Bug Depends on:    
Bug Blocks: 53572    
Attachments:
Description Flags
Patch none

Description From 2011-03-28 01:12:57 PST
script-src should block inline event handlers
------- Comment #1 From 2011-03-28 01:16:44 PST -------
Created an attachment (id=87111) [details]
Patch
------- Comment #2 From 2011-03-28 02:11:55 PST -------
(From update of attachment 87111 [details])
Seems reasonable.
------- Comment #3 From 2011-03-28 13:16:28 PST -------
(From update of attachment 87111 [details])
Clearing flags on attachment: 87111

Committed r82147: <http://trac.webkit.org/changeset/82147>
------- Comment #4 From 2011-03-28 13:16:32 PST -------
All reviewed patches have been landed.  Closing bug.
------- Comment #5 From 2011-03-28 13:38:41 PST -------
http://trac.webkit.org/changeset/82147 might have broken SnowLeopard Intel Release (Build)