Flash-Free Clipboard for the Web
hacks.mozilla.org
hacks.mozilla.org
http://stackoverflow.com/questions/14472526/will-there-ever-...
> Google Chrome and Internet Explorer both also support this API. Chrome uses
> the same restriction as Firefox (that it must be run in a user-initiated
> callback). Internet Explorer allows it to be called at any time, except it
> first prompts the user with a dialog, asking for permission to access the
> clipboard.
Seems like IE does what you want.It makes me feel very confused that this is actually true.
Glad to see that FF now supports this API, too!
By "fails" - you mean it doesn't select/highlight the color string, nor it does copy it to clipboard?
I have noticed that the click doesn't even trigger the animation of the color box too.
I guess I could put a megabytes into anyone's clipboard now when they click on any link on a website.
window.prompt("Press Ctrl-C then Enter", text);
I don't want sites to be able to randomly clear my clipboard.There is no API for reading from the clipboard, just writing to it.
The benefits of having a flashless copy/cut function greatly outweigh the off chance some random site will copy something stupid to your clipboard if you interact with it.
This article doesn't mention "paste" specifically, but the footnote[1] in the "paste" section says:
"[1] Before Firefox 41, clipboard capability needed to be enabled in the user.js preference file. See A brief guide to Mozilla preferences for more information. In Firefox 41 and later, clipboard capability are enabled by default in any event handler that is able to pop-up a window (semi-trusted scripts)."
This footnote is not attached to any other command, and thus "paste" is singled out. This could just be a documentation error, or maybe they didn't want to highlight that paste was also being enabled. I don't have a FF v41 in order to test what the actual behavior is.
[0] - https://developer.mozilla.org/en-US/docs/Web/API/Document/ex...
I believe that footnote is a doc error, since copy/cut are enabled w/o user.js override on FF 41+.
I don't know if there is any current plans to make "paste" available for all scripts - I don't think there would be because of the obvious concerns.
While using Flash just for clipboard copying is not ideal, it seems easier to block Flash and stop sites from doing this (and other annoying things Flash is known for, like ads and autoplaying videos...) than blocking small parts of JavaScript APIs integrated into the browser.
I was hoping this would let me get rid of that crufty text area. It's a serious quality and performance liability, and in certain special cases even ruins the UX. But it looks like that is not the case. Le sigh.
Couldn't you bypass this by creating an invisible button, and then simulating a click event?
I'm sure it's tricky to ensure this, though. Like pop-up blocking.
I guess Mozilla have weighed up the convenience/security balance of browser control of the clipboard, and have put in a minimal protection scheme to make it clear that code should not play with it behind the user's back, but Mozilla knows that they can't really stop it.
How? This security mechanism has been used for (among other things) popups for years now, and the only way it's been worked around is by attaching click handlers to links the user is likely to click.
Basically, the user will click something at some point, the page can then unexpectedly put malicious stuff into the clipboard. No amount of protecting will stop this.
But Mozilla just re-enabled this exploit and I don't think it can be turned off.
User-initiated != user-approved, at least not unless the user is specifically asked. (Like by, say, prompting allow/allowalways / deny / denyalways)
Trust me, selecting text is not a problem. I haven't seen a place where click to select was a life savior.