Should note here what Jas and I chatted about. some mitigations must
still be mandatory, since Safari and some old Chromes still suffer from
the Function parsing bug
https://code.google.com/p/google-caja/issues/detail?id=1616
This may not be the last time we find out that some mitigations must be
mandatory, so we should fix this to support future decisions about which
mitigations are mandatory on what browsers. This will be easier given
Kevin's suggestion that it should be up to SES clients which test
failures they are willing to tolerate, and how they wish to tolerate
them.
https://codereview.appspot.com/7381051/
--
---
You received this message because you are subscribed to the Google Groups "Google Caja Discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.