*grr* Before this makes sense, you need to truncate the host part of long URLs from the left, and not from the right. And you must make the URL bar mandatory by default (dom.disable_window_open_feature.location is still false in the shipped configuration).
Why is it when you suggest a security improvement, people respond by telling you about different ones you should make? *grr* ;-)
Yes, this is not a magic bullet on its own, and yes, it doesn't work if the user can't see the information. Happy? :-)
Gerv _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
