summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMoonchild <moonchild@palemoon.org>2023-11-13 19:28:44 +0100
committerMoonchild <moonchild@palemoon.org>2023-11-14 12:42:58 +0100
commit7e60482d8090a43e00957f3d6fc87f31d7ea65a1 (patch)
treeb0e2eaa31058dba81b2b02b6775cd73c028695d0
parent10b3237e528aac39830fc2f0dcb452a87150bd0a (diff)
downloaduxp-7e60482d8090a43e00957f3d6fc87f31d7ea65a1.tar.gz
No issue - Stop supporting data: scheme in SVG <use> elements.
-rw-r--r--dom/svg/SVGUseElement.cpp11
1 files changed, 11 insertions, 0 deletions
diff --git a/dom/svg/SVGUseElement.cpp b/dom/svg/SVGUseElement.cpp
index acd8941b4e..8da90634ad 100644
--- a/dom/svg/SVGUseElement.cpp
+++ b/dom/svg/SVGUseElement.cpp
@@ -426,6 +426,17 @@ SVGUseElement::LookupHref()
nsCOMPtr<nsIURI> targetURI;
nsContentUtils::NewURIWithDocumentCharset(getter_AddRefs(targetURI), href,
GetComposedDoc(), baseURI);
+
+ // Do not allow 'data:' schemes in <use> elements.
+ // See spec update: https://github.com/w3c/svgwg/pull/901
+ if (targetURI) {
+ bool isData;
+ mozilla::Unused << targetURI->SchemeIs("data", &isData);
+ if (isData) {
+ return;
+ }
+ }
+
mSource.Reset(this, targetURI);
}