From e9afcc9ec3e990eb1ebc79790fcf5048372858c1 Mon Sep 17 00:00:00 2001 From: jmoenig Date: Wed, 18 Sep 2013 15:34:59 +0200 Subject: prevent costumes with imported CORS-tainted canvases expected to fix #155, #154, #151, #148, #147, #127 for future projects --- gui.js | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) (limited to 'gui.js') diff --git a/gui.js b/gui.js index c11793e..e68d62c 100644 --- a/gui.js +++ b/gui.js @@ -68,7 +68,7 @@ sb, CommentMorph, CommandBlockMorph*/ // Global stuff //////////////////////////////////////////////////////// -modules.gui = '2013-September-17'; +modules.gui = '2013-September-18'; // Declarations @@ -1488,6 +1488,19 @@ IDE_Morph.prototype.droppedImage = function (aCanvas, name) { aCanvas, name ? name.split('.')[0] : '' // up to period ); + + if (costume.isTainted()) { + this.inform( + 'Unable to import this image', + 'The picture you wish to import has been\n' + + 'tainted by a restrictive cross-origin policy\n' + + 'making it unusable for costumes in Snap!. \n\n' + + 'Try downloading this picture first to your\n' + + 'computer, and import it from there.' + ); + return; + } + this.currentSprite.addCostume(costume); this.currentSprite.wearCostume(costume); this.spriteBar.tabBar.tabTo('costumes'); -- cgit v1.3.1