Files
sousa-gecko/testing/web-platform/tests/css/css-ui/reference/text-overflow-string-003-ref.html
T
Minseong Kim 0b71e2f9ca Bug 1982478 [wpt PR 54243] - TextOverflow: Compute ellipsis text with string, a=testonly
Automatic update from web-platform-tests
TextOverflow: Compute ellipsis text with string

This CL updates `LineTruncator` to respect a <string> value for the
text-overflow CSS property.

While this feature provides more flexibility for web developers,
allowing a custom string for `text-overflow` can introduce security
concerns in privileged UI contexts. A malicious actor could use this to
spoof filenames or other sensitive text.

To mitigate this risk, this CL also ensures that built-in UI controls
force `text-overflow: ellipsis !important;`. This prevents the custom
string value from being applied to sensitive system UI, protecting users
from potential spoofing attacks.

Spec: https://drafts.csswg.org/css-overflow-4/#text-overflow

Bug: 41492459
Change-Id: I95d2d07d70e548b7395a6d68c42ecb61cab46625
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6773707
Reviewed-by: Andreu Botella <abotella@igalia.com>
Reviewed-by: Ian Kilpatrick <ikilpatrick@chromium.org>
Commit-Queue: Minseong Kim <jja08111@gmail.com>
Cr-Commit-Position: refs/heads/main@{#1499889}

--

wpt-commits: f007894c5fdcb709266d84ff808eff3bbd8f6f17
wpt-pr: 54243
2025-08-19 11:11:29 +00:00

21 lines
503 B
HTML

<!DOCTYPE html>
<meta charset="utf-8">
<title>CSS Basic User Interface Reference File</title>
<link rel="author" title="Minseong Kim" href="mailto:jja08111@gmail.com">
<link rel="stylesheet" type="text/css" href="/fonts/ahem.css" />
<style>
div {
font-size: 10px;
}
span {
font-family: Ahem;
font-size: 30px;
}
</style>
<body>
<p>Test passes if there is an 🟢😀🤷‍♂️ after a black rectangle below.</p>
<div>
<span>Tes</span>🟢😀🤷‍♂️
</div>
</body>