@mjtsai As most apps using sparkle don't Quarantine files they create, Gatekeeper is never invoked in the first place.
-
-
- View other replies
-
@rosyna Did anyone imply otherwise? -
@mjtsai I inferred it from "This seems like more of a WebKit vulnerability" -
@rosyna What I meant by that is, why is WebKit executing any non-JavaScript code? -
@mjtsai It's passing it to LaunchServices (as WebKit does for other protocol handlers). Quarantine normally prevents execution. -
@rosyna I get that, but I don’t understand why I would want my browser to be able to do that silently, especially via JavaScript. -
@mjtsai You wouldn't want your browser to. But you do want WebKit to be able to do so. It's used in app documentation. -
@mjtsai Well, you'd want WebView to do it. - Show more
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Rosyna Keller