diff --git a/content/html/content/src/nsHTMLInputElement.cpp b/content/html/content/src/nsHTMLInputElement.cpp
index 1e199a17bb5e..3958d0304e42 100644
--- a/content/html/content/src/nsHTMLInputElement.cpp
+++ b/content/html/content/src/nsHTMLInputElement.cpp
@@ -1441,6 +1441,19 @@ nsHTMLInputElement::PreHandleEvent(nsEventChainPreVisitor& aVisitor)
// We must cache type because mType may change during JS event (bug 2369)
aVisitor.mItemFlags |= NS_STATIC_CAST(PRUint8, mType);
+
+ // Fire onchange (if necessary), before we do the blur, bug 357684.
+ if (aVisitor.mEvent->message == NS_BLUR_CONTENT) {
+ nsIFrame* primaryFrame = GetPrimaryFrame();
+ if (primaryFrame) {
+ nsITextControlFrame* textFrame = nsnull;
+ CallQueryInterface(primaryFrame, &textFrame);
+ if (textFrame) {
+ textFrame->CheckFireOnChange();
+ }
+ }
+ }
+
return nsGenericHTMLElement::PreHandleEvent(aVisitor);
}
diff --git a/layout/forms/nsTextControlFrame.cpp b/layout/forms/nsTextControlFrame.cpp
index ed8959bce4ca..427f3c93762f 100644
--- a/layout/forms/nsTextControlFrame.cpp
+++ b/layout/forms/nsTextControlFrame.cpp
@@ -372,7 +372,7 @@ nsTextInputListener::Blur(nsIDOMEvent* aEvent)
mFrame->SetHasFocus(PR_FALSE);
- return mFrame->CheckFireOnChange();
+ return NS_OK;
}
// END nsIFocusListener