Sat, 03 Jan 2015 20:18:00 +0100
Conditionally enable double key logic according to:
private browsing mode or privacy.thirdparty.isolate preference and
implement in GetCookieStringCommon and FindCookie where it counts...
With some reservations of how to convince FindCookie users to test
condition and pass a nullptr when disabling double key logic.
michael@0 | 1 | <!DOCTYPE html> |
michael@0 | 2 | <html> |
michael@0 | 3 | <head> |
michael@0 | 4 | <meta charset="UTF-8"> |
michael@0 | 5 | <script> |
michael@0 | 6 | |
michael@0 | 7 | function boom() |
michael@0 | 8 | { |
michael@0 | 9 | // This shouldn't leak |
michael@0 | 10 | var frame = document.getElementById("f"); |
michael@0 | 11 | var frameWin = frame.contentWindow; |
michael@0 | 12 | document.body.removeChild(frame); |
michael@0 | 13 | frameWin.navigator; |
michael@0 | 14 | } |
michael@0 | 15 | |
michael@0 | 16 | </script> |
michael@0 | 17 | </head> |
michael@0 | 18 | |
michael@0 | 19 | <body onload="boom();"> |
michael@0 | 20 | <iframe id="f" src="data:text/html;charset=utf-8,1"></iframe> |
michael@0 | 21 | </body> |
michael@0 | 22 | </html> |