14. The data: URLs can be used only for following
elements and attributes
object
img
input type=image
link
CSS properties that accept URL as a value
(e.g., background, background-image and etc.)
AVTOKYO2015Nov 14, 2015 5
IE cannot open data:text/html
15. ↑ Firefox ↑ Chrome
<iframe src=”data:text/html,test”></iframe>
AVTOKYO2015Nov 14, 2015 6
Other web browsers
17. In Firefox, content from data: URLs inherits the
origin from the document that loaded the URL in
an iframe and etc.
AVTOKYO2015Nov 14, 2015 8
Inherits the origin from the opener
19. Its behavior is sometimes completely different
among browsers
Potential vulnerabilities introduced by such
'self-indulgent' implementations
Corresponding spec is often not disclosed
AVTOKYO2015Nov 14, 2015 12
data: URL is messy