Skip to content

Javascript can create/resize windows to consume the entire desktop

Skruffy reports:

04:00 < skruffy> mikeperry: it's possible to steal screen size with making user click some link, so it does window.open(with over9000xover9000 size) or does with resizeto(). If opened with one tab then no need click even.

This is probably too obvious to be regularly used by advertisers, but we should figure out a way to fix it.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information