Comment #3 on issue 1274 by metaweta: Current "virtualize" strategy isn't safe
http://code.google.com/p/google-caja/issues/detail?id=1274

I suppose the convenience you're referring to is for coding within the caja libraries? I can see that it would be more convenient to write the shorter expression.

However, I'm more concerned with innocent code: if we don't virtualize, there's no way for innocent code to work safely, since guest code can overwrite the prototype data properties and innocent code doesn't know about the wonderbar ones.



Reply via email to