Understood and thanks.
If users are worried, they can just disable javascript for a book until we fix this in the next release.
I think I going to try to deny all custom protocols in acceptNavigationRequest, and for file:/// protocols, make sure that will be in the current epub folder, or in our internal mathjax location or in our current user user css location, otherwise reject them.
Thanks again,
KevinH
|