On Mon, 11 May 2009 15:10:57 +0200, wrote:
> I received an email from Arve explaining the possible "spoofing"
> scenario.
Oops. I thought I'd sent that mail to everyone, and not just to Ivan personally.
> He says this, and I think he is right:
>
>> Forgive my ignorance, but... "spoofing attack
I received an email from Arve explaining the possible "spoofing"
scenario.
He says this, and I think he is right:
> Forgive my ignorance, but... "spoofing attack"? O_o
1. Widget A is started in "Floating mode"
2. Widget A requests, and gets a mode change to "Application mode"
3. Widget A creates
On 5/11/09 1:43 PM, ivan.demar...@orange-ftgroup.com wrote:
Forgive my ignorance, but... "spoofing attack"? O_o
I guess Arve means click jacking.
I'll explain the scenario I have in mind:
- Widget calls the API "requestModeChange();"
- WUA checks if that mode is valid (the string is valid)
Forgive my ignorance, but... "spoofing attack"? O_o
I'll explain the scenario I have in mind:
- Widget calls the API "requestModeChange();"
- WUA checks if that mode is valid (the string is valid) and if the WUA
"likes" the mode (there could be WUA that supports only "fullscreen",
for example)
-
On Mon, 11 May 2009 13:14:40 +0200, wrote:
> About the "widget requesting a resize", I sent in the past an email to
> Arve about something similar but not quite the same: a sort of "request
> mode change" or something. This would allow widgets to ASK the WUA for
> "mode change".
> Any news about
Hello.
Better late then never: I sent this email 2 months ago :D
But I see the flux of emails everyday on this mailing list, and I
totally understand!
Anyway, funny enough, just this morning I was saying to some colleagues
that there is no current support in the config.xml for "declaring
supporte
Hi Jere,
Let me try to clarify my thoughts...
Note I'm actually suggesting an amended C3: one locale per resource, and
one locale for element-based localization.
For folder-based localization, my rationale is that it's useful to view
a widget package as a local HTTP server because it allows