<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>8818</bug_id>
          
          <creation_ts>2010-01-26 15:47:23 +0000</creation_ts>
          <short_desc>Remove the srcdoc attribute</short_desc>
          <delta_ts>2010-10-04 14:29:32 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>pre-LC1 HTML5 spec (editor: Ian Hickson)</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Windows XP</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>NE, TrackerIssue</keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Shelley Powers">shelleyp</reporter>
          <assigned_to name="Ian &apos;Hixie&apos; Hickson">ian</assigned_to>
          <cc>ian</cc>
    
    <cc>jirka</cc>
    
    <cc>julian.reschke</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-admin</cc>
    
    <cc>public-html-wg-issue-tracking</cc>
    
    <cc>shelleyp</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>31239</commentid>
    <comment_count>0</comment_count>
    <who name="Shelley Powers">shelleyp</who>
    <bug_when>2010-01-26 15:47:23 +0000</bug_when>
    <thetext>This recent entry does not have universal acceptance, and the group was still discussing it when the editor added it to the specification. 

The supposed use case for this attribute is weblog comments, but concerns about HTML security have been resolved with weblog and other application comments years ago. In addition, support for this attribute could give the impression that online sites don&apos;t need any other security, which is false. Script injection is only one aspect of security related to weblog comments, and considered a fairly trivial one at that.

This needs to be removed from the specification.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>31932</commentid>
    <comment_count>1</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2010-02-14 02:59:23 +0000</bug_when>
    <thetext>EDITOR&apos;S RESPONSE: This is an Editor&apos;s Response to your comment. If you are satisfied with this response, please change the state of this bug to CLOSED. If you have additional information and would like the editor to reconsider, please reopen this bug. If you would like to escalate the issue to the full HTML Working Group, please add the TrackerRequest keyword to this bug, and suggest title and text for the tracker issue; or you may create a tracker issue yourself, if you are able to do so. For more details, see this document:
   http://dev.w3.org/html5/decision-policy/decision-policy.html

Status: Rejected
Change Description: no spec change
Rationale: I&apos;m happy to remove this attribute from the W3C HTML5 specification if that&apos;s what the working group wants. The last time I removed a feature based on a bug report such as this, I started a minor war, however, so I suggest that you raise this via the change proposal process if you really feel this way.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>31950</commentid>
    <comment_count>2</comment_count>
    <who name="Shelley Powers">shelleyp</who>
    <bug_when>2010-02-14 04:38:53 +0000</bug_when>
    <thetext>Since you were the one putting srcdoc into the HTML5 specification, and the change wasn&apos;t based on any use case or requirement put forward by any other individual, I&apos;m assuming you had a good reason for doing so. Evidently not, since you&apos;re not incorporating the reason into the WONTFIX rationale. 

</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>31953</commentid>
    <comment_count>3</comment_count>
    <who name="Shelley Powers">shelleyp</who>
    <bug_when>2010-02-14 04:42:09 +0000</bug_when>
    <thetext>Opened as Tracker Issue 100:

http://www.w3.org/html/wg/tracker/issues/100</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>32372</commentid>
    <comment_count>4</comment_count>
    <who name="Jirka Kosek">jirka</who>
    <bug_when>2010-02-18 08:46:49 +0000</bug_when>
    <thetext>There is additional unrelated issue with srcdoc which was not mentioned previously in this bug. Content of srcdoc contains unescaped markup. This is not compatible with XML serialization of HTML5. So if there ever should be something like srcdoc, then it should be subelement of iframe not attribute.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>32636</commentid>
    <comment_count>5</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2010-02-25 02:32:38 +0000</bug_when>
    <thetext>Please file a new bug for new issues. (I don&apos;t think that comment 4 makes sense, though; XML supports escaping content in attributes just like in element contents.)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>