There is no API for reading from the clipboard, just writing to it.
The benefits of having a flashless copy/cut function greatly outweigh the off chance some random site will copy something stupid to your clipboard if you interact with it.
There is no API for reading from the clipboard, just writing to it.
The benefits of having a flashless copy/cut function greatly outweigh the off chance some random site will copy something stupid to your clipboard if you interact with it.
This article doesn't mention "paste" specifically, but the footnote[1] in the "paste" section says:
"[1] Before Firefox 41, clipboard capability needed to be enabled in the user.js preference file. See A brief guide to Mozilla preferences for more information. In Firefox 41 and later, clipboard capability are enabled by default in any event handler that is able to pop-up a window (semi-trusted scripts)."
This footnote is not attached to any other command, and thus "paste" is singled out. This could just be a documentation error, or maybe they didn't want to highlight that paste was also being enabled. I don't have a FF v41 in order to test what the actual behavior is.
[0] - https://developer.mozilla.org/en-US/docs/Web/API/Document/ex...
I believe that footnote is a doc error, since copy/cut are enabled w/o user.js override on FF 41+.
I don't know if there is any current plans to make "paste" available for all scripts - I don't think there would be because of the obvious concerns.
While using Flash just for clipboard copying is not ideal, it seems easier to block Flash and stop sites from doing this (and other annoying things Flash is known for, like ads and autoplaying videos...) than blocking small parts of JavaScript APIs integrated into the browser.