-
Notifications
You must be signed in to change notification settings - Fork 20
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
body /deep/ span
reveals cleartext
#7
Comments
body /deep/ span
reveals cyphertextbody /deep/ span
reveals cleartext
confirmed. thanks for reporting. |
http://dev.w3.org/csswg/css-scoping/ for my own reference |
Any update on this? With the cleartext availability your extension offers nothing more than a snakeoil. |
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The /deep/ combinator can cross the shadow boundary, allowing a host script read/write access the same cleartext DOM presented to the user.
A parent application can easily get all ShadowCrypt cleartext on a page:
Not sure there's a way around it at this point.
The text was updated successfully, but these errors were encountered: