6 ms·
for local files as well?
by throwaway0x7E6 4y ago
for local files as well?
- mprime1 4y agoYes. If that wasn't the case, then "HTML virus" would be a thing: I send you an HTML file and, if you open it, it read files from your hard drive and uploads them to my server.
- throwaway0x7E6 4y agoI should have clarified - I mean I was wondering if any browsers block fetch to remote URLs from local files I do vaguely recall encountering some problem I didn't expect when I was making a tool contained in a local html file, but I dont remember which browser I was using at the time
- jefftk 4y agoThe problem with your scenario is the reading the local files without permission, not the use of the crypto API.
- mprime1 4y agoYou are right, I'm conflating 2 issues. I'm pretty sure Brave was blocking window.crypto but can't remember if it was on a file or over plain HTTP
- jefftk 4y agoBlocking crypto on http:// http:// is to spec (aside from localhost) and all the browsers do that. Blocking crypto on file:// is not to spec, and testing above (https://news.ycombinator.com/item?id=34084526 https://news.ycombinator.com/item?id=34084526) none of the browsers do that.
- mprime1 4y agoIt's been a while and I don't remember the details. All I remember is that I was developing the secret 'creator' code using Brave (my default unsecured browser) and at some point I had to switch to Safari (which I normally save for trusted websites only). It's possible it was a red herring, and I switched browser but the problem was something else I did at the same time.