Unless I am missing how using our own trusted protocol actually helps instead of moving the problem, perhaps it would be better to instead intercept it in acceptNavigationRequest and reject any file:/// url that is outside the bounds of the ebook folder. Javascript generated target links do pass through there and can be stopped at that point.
|