00:10
<Dashiva>
http://heideri.ch/jso/
00:10
<Dashiva>
The page shoots itself in the foot by having "attacks" that require the attacker to be able to create on* attributes already
00:10
<AryehGregor>
Sounds like "When we add new attributes, people who were blacklisting attributes are screwed".
00:11
<AryehGregor>
<video poster> sounds like a sneaky one, though, you'd expect someone might fall for that. Does javascript: work for <img src>?
00:13
<Dashiva>
Don't think so. Don't see why it should work for poster either.
00:18
<Dashiva>
Looks like it's just a bug in Opera
00:19
<Dashiva>
All the other cases require that the attacker already can write arbitrary markup, so I guess that's 0 new attacks
00:19
<AryehGregor>
As usual.
04:22
<wirepair>
besides the sandbox attribute, does anyone see/know of anything in html5 that will help increase security/make it easier for developers to create secure apps?
04:58
<Hixie>
wirepair: security features are baked in from the ground up, so it's hard to point to them
05:18
<wirepair>
hixie yeah
05:19
<wirepair>
just wondered if something additional like sandbox would provide developers with the ability to secure their web apps
05:39
<Hixie>
wirepair: there's things like the Origin header
05:39
<Hixie>
wirepair: might be some other features here and there
05:40
<Hixie>
wirepair: generally the idea is to make it automatic that things be secure, though
05:55
<wirepair>
cool, thanks
06:32
<annevk>
http://beltzner.ca/mike/2010/05/10/firefox-4-fast-powerful-and-empowering/
06:32
<annevk>
wtf is it with slideshare
06:32
<annevk>
don't people realize slideshare stinks and requires a plugin
06:32
<annevk>
grmbl
06:47
<virtuelv>
annevk: pragmatically, it lets people do what people want
06:47
<virtuelv>
upload their powerpoints and keynote presentations
06:48
<virtuelv>
and it provides embedding functionality
06:49
<karlcow>
http://www.learningjquery.com/2010/05/now-you-see-me-showhide-performance
06:52
<MikeSmith>
krijnh server not responding>
06:53
<annevk>
there's no reason slideshare needs Flash
06:54
<karlcow>
annevk: there is one.
06:54
<karlcow>
burning CPU cycles for the glory of computing :p
07:23
<annevk>
What's also interesting about this CORS thing is that e.g. WebSocket has exactly the same semantics...
07:41
<franksalim>
annevk, a consistent security models is good
07:41
<franksalim>
*model
07:42
<annevk>
Indeed, but people argue against CORS but not against WebSocket
07:42
<Hixie>
lots of people arguing against websocket for other reasons
07:42
<franksalim>
they don't argue against websocket?
07:42
<Hixie>
we already have enough arguments thanks :-)
07:43
<franksalim>
hmm yes
07:43
<annevk>
would be a nice way to get them off my lawn :p
07:44
<Hixie>
i'll send you some of mine!
07:44
<Hixie>
mutually assured destruction!
07:46
<annevk>
heh
07:46
<annevk>
Hixie, you have some time for the complete.html thingy now?
07:46
<Hixie>
sure, now's a good time
07:46
<Hixie>
'sup
07:47
<othermaciej>
hello Hixie
07:47
<Hixie>
hey othermaciej
07:47
<annevk>
I guess you want to have the copy without the absolute URLs
07:47
<annevk>
and I'm generating the zip file already
07:47
<Hixie>
so long as it works, i don't mind if they're absolute or not
07:48
<annevk>
I guess I just need to give you a URL and you need to give one to me
07:48
<Hixie>
i guess ping /specs/web-apps/current-work/do-multipage-complete-update
07:49
<Hixie>
what should i fetch?
07:49
<annevk>
http://html5.org/complete/whatwg.org/complete.zip
07:50
<annevk>
just doing a wget on that URL works I suppose?
07:50
<Hixie>
yup
07:50
<Hixie>
or will, once i've written the script
07:56
<annevk>
I pm'ed the generate URL
07:56
<annevk>
pm'd even
07:57
<Hixie>
thanks
07:57
<annevk>
I guess once that is all set up MikeSmith can remove the mailing list hook
07:58
<MikeSmith>
yep
07:58
<MikeSmith>
just lemme know when to flip the switch
09:14
MikeSmith
wonders if Richard Clark is on IRC
09:24
Hixie
gets his script all confused
09:39
<annevk>
hsivonen, hah, http://library.gnome.org/users/palimpsest/stable/advanced.html.en is brilliant
09:44
<annevk>
http://limpet.net/mbrubeck/2010/05/11/fennec-meta-viewport.html -- '<meta name="viewport"> is a good example of browsers innovating exactly how Sachin Agarwal thinks they should.'
09:44
<annevk>
it's also pretty ugly
09:44
<Hixie>
and a layering violation
09:47
<hsivonen>
Hixie: supported by 3 of the top 4 engines. time to bite the bullet and spec it.
09:47
<Hixie>
that's anne's problem
09:50
<annevk>
not really, someone can write a standalone spec for it and add it to the metaextensions wiki
09:54
<Hixie>
ok, finally got the multipage scripts figured out
09:54
<Hixie>
man i caused a lot of damage while doing that
09:55
<hsivonen>
whoa. http://my.opera.com/ODIN/blog/opera-mobile-10-for-nokia-n900-n800-n810-maemo-standards-support says Opera on desktop support SQL database
09:55
<Hixie>
didn't we know that?
09:55
<hsivonen>
Hixie: I didn't.
09:55
<hsivonen>
does it use sqlite?
09:56
<Hixie>
i assume so
09:56
<zcorpan_>
yes it does
09:57
<hsivonen>
ok
09:57
<zcorpan_>
http://my.opera.com/core/blog/2010/03/03/persistent-client-side-storage-for-your-persistent-needs
09:58
<hsivonen>
a bit odd not to have it on Maemo if you have it on desktop, considering WebKit's competitive position in the mobile space
09:59
<hsivonen>
so Maemo now has 3 of the top 4 browser engines available
09:59
<hsivonen>
I guess that's the broadest coverage for any mobile platform now that Gecko for Windows Mobile was discontinued
10:27
<roc>
I just read that Sachin Agarwal blog post and my head exploded
10:34
<hsivonen>
roc: the post has been pretty successful at getting attention
10:34
<roc>
sure
10:36
<roc>
outrageous posts get attention
10:42
<karlcow>
well I guess jetlag is at least good for data mining/archeology.
10:42
<annevk>
finally figured out how to get more sensible pages out of spec splitter
10:42
<annevk>
Hixie, maybe you should rename the id crossDocumentMessaging as it is not a very nice or consistent page name
10:43
<karlcow>
the first mention of srt, I found on public-html is sept 2008 by Lachlan
10:46
<annevk>
isn't John Foliot effectively asking for addition there?
10:47
<annevk>
"then clear instruction and specifications on how to 'in-code' provide the out-band solution must also be provided"
10:47
<karlcow>
annevk: yep
10:48
<annevk>
fun stuff
11:01
<hsivonen>
so Opera on Maemo has about zero platform integration. not even low-hanging fruit like right icon in the right menu
11:02
<hsivonen>
but the responsiveness and graphics speed is really impressive
11:02
<hsivonen>
on N800
11:09
<Hixie>
annevk: done
11:13
<annevk>
cool
11:13
<annevk>
btw, I now have enough understanding of spec-splitter.py that I can create whatever split people desire
11:14
<Hixie>
nice
11:14
<annevk>
for everyone who didn't know yet: http://www.whatwg.org/specs/web-apps/current-work/complete/
11:14
<annevk>
and when that copy is down: http://html5.org/complete/
11:15
<Hixie>
looks like the reviewer script is dead on the whatwg copy there
11:15
<Hixie>
wonder what's up with that
11:15
<annevk>
hmm, maybe I should use absolute links after all?
11:16
<Hixie>
aha, no
11:16
<Hixie>
problem with fixBrokenLink()
11:16
<Hixie>
aha, no link-fixup.js
11:16
<Hixie>
you have to include one of those in the zipfile, i think
11:17
<annevk>
can't you make the links absolute?
11:17
<annevk>
i mean like /path-to-script
11:17
<Hixie>
the scripts are absoute
11:17
<Hixie>
absolute
11:17
karlcow
had a very brief image of annevk dancing at the Bolchoi and doing a split
11:17
<Lachy>
oh, nice multipage complete version. That could be useful, though I'll stick with single page.
11:18
<Hixie>
but you need to include a link-fixup.js specially designed for complete/'s structure
11:18
<Hixie>
equivalent to http://www.whatwg.org/specs/web-apps/current-work/multipage/link-fixup.js
11:18
<Hixie>
which apparently uses http://www.whatwg.org/specs/web-apps/current-work/multipage/fragment-links.js
11:18
<Hixie>
both are provided by philip
11:18
<Hixie>
in his tarball
11:19
<annevk>
ah
11:20
<Hixie>
the problem is that script is invokes before init()
11:21
<Hixie>
so if that script fails, init() never runs
11:21
<Hixie>
and the other scripts don't get loaded
11:23
<annevk>
thanks
11:23
<annevk>
hopefully fixed
11:26
<Hixie>
nice
11:30
<annevk>
removed the script on html5.org/complete as it doesn't work due to cross-origin issues
11:31
<Hixie>
some will work
11:31
<Hixie>
others not so much
11:33
<Hixie>
does dfn.js not worm in ff?
11:33
<Hixie>
or did i break it?
11:34
<Hixie>
oh i broke it
11:34
<Hixie>
nm
12:48
<hsivonen>
the notion of whitespace is such a mess
12:48
<hsivonen>
it seems various places in Gecko agree that space, \t and \n are whitespace
12:48
<hsivonen>
\r, \f and \v depend
12:48
<hsivonen>
sigh
12:48
<hsivonen>
and don't get me started about XML 1.1
12:55
<hsivonen>
Hixie: why does area coords parsing in HTML5 treat only space as a delimiter (not tab, newline, etc.)?
12:55
<zcorpan_>
hsivonen: iirc for ie compat, but i'm not 100% sure
12:56
<hsivonen>
zcorpan_: What do Opera and WebKit do?
12:56
<hsivonen>
Gecko accepts even \v!
12:57
<zcorpan_>
hsivonen: opera implements the spec, or possibly an earlier version of the spec where there was no special treatment for funny characters or something
12:57
<zcorpan_>
hsivonen: don't remember what webkit does
12:58
<hsivonen>
zcorpan_: ok
12:58
<hsivonen>
I'll file this away, because these other whitespace bugs are distracting me from the whitespace bug I'm trying to fix
12:58
<Philip`>
http://lists.w3.org/Archives/Public/public-html/2009Jan/0079.html ?
12:59
<hsivonen>
Filed as https://bugzilla.mozilla.org/show_bug.cgi?id=565031
13:00
<zcorpan_>
hsivonen: i don't mind changing the spec wrt whitespace in coords
13:39
<annevk>
hsivonen, isn't XML 1.1 dead?
13:45
<annevk>
I wonder why the chairs are so vocal about splitting... I guess there was some backchannel chatter
13:51
<nessy>
annevk: I think it has a lot to do with keeping the choice of external text format independent of HTML5
13:52
<nessy>
png, jpeg, ogg, mpeg4 - none of these are specified as part of HTML5
13:52
<nessy>
and nor should they by - there may be better formats in the future that the video, audio and img elements will have to support!
13:53
<nessy>
it's really the same for external text associations for video and audio and a format definition should not be inside the spec
13:54
<annevk>
text/cache-manifest is in HTML5
13:54
<annevk>
as are text/ping, text/html-sandboxed, application/microdata+json
13:55
<Philip`>
Has anyone argued that it *should* be defined in the HTML5 document? (rather than arguing that it doesn't matter where the text exists for now and it's a waste of effort to worry about it before we even know whether it's a good enough solution that it should continue to exist)
13:55
<annevk>
Ian has
13:56
<Philip`>
Ah
13:56
<nessy>
annevk: are those supposed to be used outside the Web by other apps, too?
13:57
<annevk>
nessy, whether there will be better formats in the future is somewhat orthogonal to where formats are specified
13:57
<nessy>
not if the only format that is acceptable is the one inside the spec
13:57
<erlehmann>
nessy, at least where the consensus is clear — with the img element — it would be good to document it. after all, png, gif, jpeg ARE all supported in almost every browser.
13:58
<annevk>
if we want to make more formats acceptable we change the spec
13:58
<erlehmann>
without baseline formats you get compatibility nightmares
13:58
<erlehmann>
what annevk said.
13:58
<nessy>
you can call a format a baseline format without having it specified inside the spec
13:58
<nessy>
we wouldn't include the theora specification into html5, either, to make it a baseline format
13:59
<erlehmann>
nessy, how would an implementor know then if it isn't included ?
13:59
<nessy>
a mere sentence that this is the baseline format and a link to its specification would be completely sufficient
14:00
<nessy>
honestly, my mind boggles at the sheer idea that somebody implementing support for WebSRT in their desktop captioning application has to deal with the whole HTML5 spec!
14:00
<annevk>
why would they have to deal with the whole spec?
14:01
<nessy>
because as it's part of the HTML5 spec, how will they know there is nothing in the rest of the spec that is not relevant to their implementation
14:01
<annevk>
also these are not the reasons brought forward for splitting
14:01
<nessy>
they are my reasons
14:01
<annevk>
sure
14:01
<nessy>
and I have brought them forward
14:02
<annevk>
sure
14:02
<annevk>
but they are not what started this IRC thread :)
14:02
<nessy>
oh!
14:02
<annevk>
anyway, it seems that simply reading the WebSRT section should give them all the answers
14:03
<nessy>
seems I have to keep up with the spec reading!
14:04
<annevk>
e.g. text/cache-manifest might get separate tool support as well
14:05
<annevk>
it's pretty easy to just read the part on text/cache-manifest to figure out how to construct such files and how to read them (e.g. if you write some kind of optimization tool)
14:05
<annevk>
some definitions are reused but they are all clearly hyperlinked
14:06
<annevk>
I don't really see what all the fuss is about; it mostly seems a lot of hand waving without much clear scenarios
14:08
<nessy>
look at it this way: software is not written as one big main function either - stuff that is reused elsewhere is split into libraries - WebSRT is a "library" for me
14:09
<nessy>
and the spec is too long for its own good anyway - takes ages to load in any browser!
14:09
<hsivonen>
annevk: Some aspects of XML 1.1 are undead, though
14:10
<nessy>
btw: does anyone know why the links in the ToC at http://dev.w3.org/html5/spec/Overview.html don't work?
14:10
<nessy>
I guess it's just the #websrt one that doesn't ...
14:11
<Philip`>
nessy: http://www.whatwg.org/specs/web-apps/current-work/complete/video.html#websrt loads faster
14:12
<nessy>
yeah, I know, but I wanted to check what's in the w3c's spec
14:12
<nessy>
I always use the whatwg link :)
14:12
<Philip`>
Oops, I got confused and forgot it was still in the HTML5 documents too
14:12
<nessy>
hmm… it seems it had to do with the page not being properly loaded by my browser - forget it :)
14:21
<MikeSmith>
nessy: that link probably doesn't work because that section is recently added and so the splitter has generated a new output file for it, and I've not yet committed that to cvs
14:21
<MikeSmith>
I'll take a look noew
14:21
<nessy>
it worked after a reaload actually
14:21
<nessy>
nothing to worry about
14:59
<annevk>
hsivonen, fwiw, treating CR as TAB without tab stops is not something I really understand
15:27
<webr3>
re spaces; here's a list of all the one I know:
15:27
<webr3>
\u0020 //SPACE | \u00A0 //NO-BREAK SPACE | \u1361 //ETHIOPIC WORDSPACE | \u1680 //OGHAM SPACE MARK | \u2002 //EN SPACE | \u2003 //EM SPACE | \u2004 //THREE-PER-EM SPACE | \u2005 //FOUR-PER-EM SPACE | \u2006 //SIX-PER-EM SPACE | \u2007 //FIGURE SPACE | \u2008 //PUNCTUATION SPACE | \u2009 //THIN SPACE | \u200A //HAIR SPACE | \u200B //ZERO WIDTH SPACE | \u202F //NARROW NO-BREAK SPACE | \u205F //MEDIUM MATHEMATICAL SPACE | \u2408
15:28
<annevk>
oh hey webr3, didn't know you were on IRC
15:28
<webr3>
yeah i am
15:29
<webr3>
almost feel like saying sorry about the noise; but at the same time i see it as an issue, that probably can't be addressed! web's safe so it's cool
15:29
<zcorpan_>
http://simon.html5.org/dump/ecmascript-whitespace.txt
15:29
<webr3>
zcorpan_: cheers
15:30
<zcorpan_>
the "opera" column is out of date
15:30
<annevk>
webr3, discussion is good
15:30
<webr3>
zcorpan_ maybe check for \u303F - is missing off that page
15:30
<webr3>
annevk: agreed
15:31
<zcorpan_>
webr3: i checked for all of BMP
15:31
<webr3>
:)
15:31
<zcorpan_>
in o10.5x i get:
15:31
<zcorpan_>
9 10 11 12 13 32 133 160 5760 6158 6159 8192 8193 8194 8195 8196 8197 8198 8199 8200 8201 8202 8203 8232 8233 8239 8287 12288 65279 65534
15:31
<webr3>
definitive list, I'll update my trim()'s!
15:35
<zcorpan_>
note that this is whitespace in ecmascript eval()
15:36
<zcorpan_>
whitespace in ecmascript source is hopefully the same
15:36
<zcorpan_>
but whitespace in other places is different
15:36
<jgraham>
"other places"?
15:36
<zcorpan_>
i mean like in html and css
15:36
<jgraham>
Ah
15:37
<jgraham>
Well yes, ECMAScript says "all other characters in unicode class Zs" or something
15:37
<jgraham>
HTML has a shor fixed list
15:37
<jgraham>
*short
15:38
<jgraham>
(ECMAScript also has a short list or doesn't-matter-what-unicode-says characters)
15:38
<zcorpan_>
the ecmascript definition is annoying because it doesn't say which version of unicode, just requires unicode 2.0 or later (or something)
15:38
<zcorpan_>
and it changes over time
15:38
<jgraham>
Indeed
15:39
<annevk>
pretty great that we are now at the point where we can argue over whitespace definitions rather than all the shit we had to emulate from IE6 :p
15:39
<jgraham>
Unicode 3.0
15:40
<jgraham>
(it says "must... Unicode 3.0 ... may ... later versions")
15:40
<annevk>
(of course, it's not quite like that, but it certainly has improved)
15:40
<jgraham>
(so even if characters are moved out of Zs in later versions, tehy still have to be recognised as whitespace)
15:40
<jgraham>
(which has happened a couple of times iirc)
15:41
<annevk>
wait what?
15:41
<annevk>
oh god
15:42
<annevk>
TC39...
15:47
<jgraham>
annevk: ?
15:47
<annevk>
you pointing out it's as inconsistent as hell
15:48
<jgraham>
Well not really
15:49
<jgraham>
It's slightly more consistent than just saying "whatever versuion of unicode you like"
15:49
<jgraham>
slightly less consistent than saying "just this set of characters"
15:50
<Dashiva>
Unicode versions are a pain no matter how you handle them...
16:02
<annevk>
jgraham, latest version would have been more consistent
16:04
<annevk>
relying on specifications not evolving is silly and codifying it is worse
16:07
<boblet>
dear cabal, I published some stuff on ruby
16:07
<boblet>
http://html5doctor.com/ruby-rt-rp-element/
16:07
<boblet>
and some supporting code snippets and notes here: http://oli.jp/example/ruby/
16:11
<Dashiva>
I like the Chinese examples
16:11
<boblet>
hehehe
16:11
<boblet>
naughty me
16:12
<boblet>
Dashiva: do you understand Chinese, or are you just exceptionally clued on about Chinese internet memes?
16:12
<MikeSmith>
boblet: nice work
16:13
<Dashiva>
The latter
16:13
<boblet>
hey Mike! thanks man
16:13
<Dashiva>
By the way, ruby is used very creatively in Japanese
16:13
<Dashiva>
Translations, clarificatioins, all kinds of weird stuff
16:15
<Dashiva>
http://dashiva.net/misc/baldr03.jpg
16:16
<Dashiva>
The ruby is ... Japanese transliterations of the English words for the translated Japanese
16:16
<boblet>
MikeSmith: you gonna be around next Tue-Thur? I’ll be in town. would be nice to catch up — maybe the W3 mixed rotenburo trip Naoko was talking about?
16:16
<boblet>
Dashiva: it’s mainly just furigana and romaji for kanji pronunciation
16:16
<Dashiva>
http://dashiva.net/misc/baldr08.jpg
16:16
<Dashiva>
This one made me smile
16:17
<boblet>
hehe
16:17
<MikeSmith>
boblet: will be at home, yeah
16:25
MikeSmith
heads away for a bit
18:31
<shepazutoo>
hsivonen: I think there's a typo in your moz post "the more maintainable code base of the HTML5 compared to Gecko’s old HTML parser." -> "the more maintainable code base of the HTML5 parser compared to Gecko’s old HTML parser."
18:33
<shepazutoo>
hsivonen: also, "<DOCTYPE !html>" -> "<!DOCTYPE html>"
18:34
annevk
was just about to point that out :)
18:36
<shepazutoo>
but overall, a nice summary, thanks, hsivonen
18:48
<hsivonen>
shepazutoo: thanks. forwarded to blizzard
18:51
<JonathanNeal>
Ahoy!
19:01
<hsivonen>
shepazutoo: fixed. thanks
19:03
<annevk>
http://googleblog.blogspot.com/2010/05/giving-voice-to-more-languages-on.html -- hmm eSpeak is GPL; I wonder what loophole is being used here
19:04
<Philip`>
annevk: They're not distributing compiled code that contains eSpeak, so the GPL obligations on releasing source code don't apply
19:05
<annevk>
Aah, so GPL can be "abused" by server applications?
19:05
<Philip`>
Yes
19:05
<Philip`>
(if you consider it abuse)
19:05
<annevk>
The people who drafted it probably do
19:05
<Philip`>
The Affero GPL is designed to prevent that situation
19:07
<annevk>
Seems like quite the loophole given all the "cloud" thingies going on
19:09
<Dashiva>
I wonder if you could sell something and include "You must forfeit your GPL-granted rights for this product" in the contract terms
19:11
<Philip`>
You can include anything you want in the contract terms
19:11
<Philip`>
People will probably happily agree to it too
19:14
<Dashiva>
But would it be legally solid?
19:14
<Philip`>
The GPL says "You may not impose any further restrictions on the exercise of the rights granted or affirmed under this License." which sounds like you could argue it covers that situation
19:16
<Dashiva>
Sounds like it, yeah
19:18
<Dashiva>
"a durable physical medium customarily used for software interchange"
19:18
<Dashiva>
Like floppies!
21:42
<AryehGregor>
Is there any way to blur out an image from JavaScript? Like you have some image at a URL, and you want to include that image, but blurred. Is this something canvas can do somehow?
21:43
AryehGregor
knows nothing about image stuff
21:45
<miketaylr>
i've seen a js lib that does that i think
21:45
miketaylr
looks
21:46
<miketaylr>
aha. AryehGregor: http://www.pixastic.com/lib/docs/actions/blur/
21:46
<miketaylr>
http://www.pixastic.com/lib/docs/actions/blurfast/ is way more intense
21:46
<AryehGregor>
Yeah.
21:46
<AryehGregor>
That's what I'm looking for.
21:47
<AryehGregor>
Hmm, MPL 1.1.
21:48
<AryehGregor>
That's not GPL-compatible, is it?
21:48
<AryehGregor>
Well, probably no one's looking too hard.
21:48
miketaylr
has no idea
21:48
<AryehGregor>
It's probably fine if I keep it served in totally separate files, I guess.
22:33
<zcorpan_>
AryehGregor: you could use an svg filter
22:34
<AryehGregor>
Seems like there's a library to do it, which already uses canvas+IE filters for IE.
22:34
<AryehGregor>
Good enough for me.
22:35
<roc>
canvas???
22:35
<roc>
SVG filters would perform a lot better
22:36
<Philip`>
SVG isn't a cool new toy, though
22:36
<zcorpan_>
svg filters in text/html is a cool new toy
22:37
<zcorpan_>
it doesn't even work in any shipping browser
22:57
<roc>
zcorpan_: svg filters in text/html works in Firefox 3.5 and later
22:57
<roc>
you just put the filter in an external SVG file