diff options
| author | jmoenig <jens@moenig.org> | 2013-09-18 15:34:59 +0200 |
|---|---|---|
| committer | jmoenig <jens@moenig.org> | 2013-09-18 15:34:59 +0200 |
| commit | e9afcc9ec3e990eb1ebc79790fcf5048372858c1 (patch) | |
| tree | d1dbf920aa3b93174adb70e9d57cf60d9c01ad98 | |
| parent | c0a0c1f4a7a9f3cfd055288817530cf7c46bb26d (diff) | |
| download | snap-yow-e9afcc9ec3e990eb1ebc79790fcf5048372858c1.tar.gz snap-yow-e9afcc9ec3e990eb1ebc79790fcf5048372858c1.zip | |
prevent costumes with imported CORS-tainted canvases
expected to fix #155, #154, #151, #148, #147, #127 for future projects
| -rw-r--r-- | gui.js | 15 | ||||
| -rwxr-xr-x | history.txt | 4 | ||||
| -rw-r--r-- | objects.js | 20 |
3 files changed, 37 insertions, 2 deletions
@@ -68,7 +68,7 @@ sb, CommentMorph, CommandBlockMorph*/ // Global stuff //////////////////////////////////////////////////////// -modules.gui = '2013-September-17'; +modules.gui = '2013-September-18'; // Declarations @@ -1488,6 +1488,19 @@ IDE_Morph.prototype.droppedImage = function (aCanvas, name) { aCanvas, name ? name.split('.')[0] : '' // up to period ); + + if (costume.isTainted()) { + this.inform( + 'Unable to import this image', + 'The picture you wish to import has been\n' + + 'tainted by a restrictive cross-origin policy\n' + + 'making it unusable for costumes in Snap!. \n\n' + + 'Try downloading this picture first to your\n' + + 'computer, and import it from there.' + ); + return; + } + this.currentSprite.addCostume(costume); this.currentSprite.wearCostume(costume); this.spriteBar.tabBar.tabTo('costumes'); diff --git a/history.txt b/history.txt index 276a187..625bb1d 100755 --- a/history.txt +++ b/history.txt @@ -1912,3 +1912,7 @@ ______ * GUI: fixed #119, #149 (accessing a shared projects requires lowercasing the username) * Portuguese translation update for SPLIT block, thanks, Manuel! * Store, Objects: prevent costumes from being drawn while they are loading, fixes parts of #154 + +130918 +------ +* Objects, GUI: prevent costumes with CORS-tainted canvases, expected to fix #155, #154, #151, #148, #147, #127 for future projects @@ -124,7 +124,7 @@ PrototypeHatBlockMorph*/ // Global stuff //////////////////////////////////////////////////////// -modules.objects = '2013-September-17'; +modules.objects = '2013-September-18'; var SpriteMorph; var StageMorph; @@ -5246,6 +5246,24 @@ Costume.prototype.thumbnail = function (extentPoint) { return trg; }; +// Costume catching "tainted" canvases + +Costume.prototype.isTainted = function () { + // find out whether the canvas has been tainted by cross-origin data + // assumes that if reading image data throws an error it is tainted + try { + this.contents.getContext('2d').getImageData( + 0, + 0, + this.contents.width, + this.contents.height + ); + } catch (err) { + return true; + } + return false; +}; + // SVG_Costume ///////////////////////////////////////////////////////////// /* |
