Open gorhill opened 10 years ago
this should be a nice feature enhancement. Websites like www.lenevo.com can be handled easily.
Test case: http://evil.hackademix.net/hsb/
Insight: the case here is less of an issue than it appears, given data uri in chromium-based browsers each have their own unique origin. Also, intercepting redirect is not a catch all solution given a data uri can also be used as a link for an <a>
tag.
Suggested through email: