Sounds like a security flaw. Why don't browsers patch it?
Sounds like a security flaw. Why don't browsers patch it?
There still is the issue of Mozilla being the only one without a direct incentive to prevent this fix from rolling out. With their whopping 3 percent market share, I doubt they'd be willing to break a web feature we've had for decades.
What use cases would it break? Why do you need a fake URL to show up when the link is hovered?
Preventing them in onclick handlers of a[href] elements would break fewer, but then you have the issue of correlating the redirect with the click. If you simply ban window.href= in the handler, sites could simply use setTimeout or set a flag and have a repeating background task trigger the redirect when the flag is set. Alternatively, you could do something like prevent all redirects X seconds after a link is clicked. Unfortunately, that would only discourage sites that are trying to be fast (like Google). Scam sites are usually slow and bloated anyways.
Why does that AJAX form need to pretend it's a link to a specific URL?
A button would have no problem, and a link that stays on the page would have no problem.
At least in Firefox, one can check easily what the actual URL is before clicking without having to copy-paste elsewhere.