And what is to keep the evil epub developer from simply using a "sigl" or calibre's FAKE_PROTOCOL scheme url to do what they want. Isn't this just moving the problem? It would be quite easy for a javascript to to get the current page url, find the newly trusted protocol/scheme and create a url using it, wouldn't it?
Last edited by KevinH; 06-06-2020 at 01:20 PM.
|