https://news.ycombinator.com/item?id=10023517
Let's not give the project a bad name for someone else's bugs.
https://news.ycombinator.com/item?id=10023517
Let's not give the project a bad name for someone else's bugs.
If people were misled into thinking pdf.js was completely to blame, then that's Mozilla's fault.
As far as I understand PDF.js used the 'PlayPreview' feature (Playpreview is the overlay you get to see to confirm you want to activate a plugin) as a 'hack' to inject PDF.js HTML content (resource://pdf.js/web/viewer.html) into the page because the plugin architecture was not flexible enough. So, even though technically PlayPreview is not part of PDF.js, the combination of PDF.js and PlayPreview specifically made it possible to inject content into PlayPreview and bypass the CSP.
https://github.com/mozilla/pdf.js/commit/4f3f983a214867011dd...
Not sure who's to blame, but like he said, there was no vulnerability in the web version.