<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.mozilla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=HeikkiToivonen</id>
	<title>MozillaWiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.mozilla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=HeikkiToivonen"/>
	<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/Special:Contributions/HeikkiToivonen"/>
	<updated>2026-10-05T07:13:10Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.10</generator>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Mobile/UI/Designs/TouchScreen&amp;diff=80638</id>
		<title>Mobile/UI/Designs/TouchScreen</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Mobile/UI/Designs/TouchScreen&amp;diff=80638"/>
		<updated>2008-01-23T00:02:51Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: /* Comments */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Touch Screen UI Design ==&lt;br /&gt;
&lt;br /&gt;
The Touch Screen UI design has the following goals:&lt;br /&gt;
&lt;br /&gt;
* 1-2 taps for most frequent activities&lt;br /&gt;
* Finger taps -- no stylus required&lt;br /&gt;
* Familiar (to desktop users) where possible&lt;br /&gt;
* Intuitive&lt;br /&gt;
&lt;br /&gt;
The design proposal described below attempts to meet all these goals.&lt;br /&gt;
&lt;br /&gt;
=== Main Screen ===&lt;br /&gt;
&lt;br /&gt;
[[Image:MobileFF-TouchUI-Main.png|frame|Main Screen]]&lt;br /&gt;
&lt;br /&gt;
The main browser screen is shown at right.&lt;br /&gt;
&lt;br /&gt;
The toolbar at the bottom contains the most frequently used functions - back/forward, zoom in/out and tabs. This toolbar cannot be hidden, and is generally present in all browser screens.  The buttons may sometimes change depending on the screen.&lt;br /&gt;
&lt;br /&gt;
Web page content is displayed in the center panel, and can be scrolled/panned directly by dragging.  Scrollbars are normally not shown to maximize screen real estate, but can be shown during scrolling to provide a visual cue of the overall page size.&lt;br /&gt;
&lt;br /&gt;
At the top of the screen is a title bar with a hideable toolbar beneath.  This toolbar has a reload button, a URL bar, and a bookmark button.&lt;br /&gt;
&lt;br /&gt;
This UI layout enables quick 1-touch access to the most frequent browser activities.&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
It may be tough to tap the title bar with your finger without hitting the URL bar by mistake.&lt;br /&gt;
&lt;br /&gt;
One thing to consider is simply scrolling the title bar off the top of the screen when you scroll down through the page, as the iPhone does.&lt;br /&gt;
&lt;br /&gt;
=== Maximized Main Screen ===&lt;br /&gt;
[[Image:MobileFF-TouchUI-Main-max.png|frame|Maximized Main Screen]]&lt;br /&gt;
&lt;br /&gt;
The URL toolbar may be hidden by tapping on the title bar.  This increases the display area for the web page.&lt;br /&gt;
&lt;br /&gt;
Tapping the title bar again re-displays the URL bar.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
The following blank lines are required!!!&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
&lt;br /&gt;
=== URL Entry Screen ===&lt;br /&gt;
&lt;br /&gt;
[[Image:MobileFF-TouchUI-Url-entry.png|frame|URL Entry Screen]]&lt;br /&gt;
&lt;br /&gt;
Tapping the URL textfield opens a new screen as shown to the right.  This screen displays a textbox at the top that displays the currently entered text.  The user may enter a search term or a URL.&lt;br /&gt;
&lt;br /&gt;
Below the URL/search-term text field is a panel that display hints from browsing and search history and bookmarks that match the entered text.  The number of hints shown depends on the display height but in any case the height of each entry field will be sufficient to allow easy touch access.  &#039;&#039;&#039;Note:&#039;&#039;&#039; Clicking on any hint will immediately launch that URL.&lt;br /&gt;
&lt;br /&gt;
The system provided software keyboard is displayed below the hints panel.  This is optional and is displayed only on touch screen devices that do not have an integrated QWERTY keyboard.&lt;br /&gt;
&lt;br /&gt;
The toolbar at the bottom has a new set of buttons.  The &amp;quot;cancel&amp;quot; button returns to the main screen, the &amp;quot;go&amp;quot; button launches the URL entered, and the &amp;quot;search&amp;quot; button invokes the user-defined web search engine with the text entered as the search term(s).&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
&lt;br /&gt;
=== Page Load Screen ===&lt;br /&gt;
&lt;br /&gt;
[[Image:MobileFF-TouchUI-Loading.png|frame|Page Load Screen]]&lt;br /&gt;
&lt;br /&gt;
When the user clicks &amp;quot;Go&amp;quot; or &amp;quot;Search&amp;quot; in the URL entry screen, the browser displays the page loading screen.&lt;br /&gt;
&lt;br /&gt;
This screen is essentially identical to the Main screen, except that the &amp;quot;reload&amp;quot; button is now a &amp;quot;Stop&amp;quot; button, and allows the user to cancel the request.&lt;br /&gt;
&lt;br /&gt;
Page download progress is displayed in the URL box.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
Changing of the reload to stop has a really nasty effect; talk to any iPhone user and you will likely encounter them griping about it. The issue is that you start a page load, decide to stop, and while that command is moving your hand to click the stop button the button changes to reload, so you end up reloading the page you tried to stop loading. Very confusing, and annoying. --Heikki&lt;br /&gt;
&lt;br /&gt;
=== History on Main Screen ===&lt;br /&gt;
&lt;br /&gt;
[[Image:MobileFF-TouchUI-Main-history.png|frame|History on Main Screen]]&lt;br /&gt;
&lt;br /&gt;
To allow easy access to browsing history, the URL box includes a history chevron at the right.&lt;br /&gt;
&lt;br /&gt;
Tapping the history chevron displays the most recently viewed pages.  The list is displayed with the most recent page at the top.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;For discussion:&#039;&#039;&#039;&lt;br /&gt;
* The toolbar icon at the bottom can show different buttons that allow the user to sort the history list in other ways - name, frequency of access, etc.&lt;br /&gt;
* The title bar and URL bar can be removed in this screen to make more room for history items.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
&lt;br /&gt;
=== Bookmarks ===&lt;br /&gt;
&lt;br /&gt;
[[Image:MobileFF-TouchUI-Bookmarks.png|frame|Bookmarks]]&lt;br /&gt;
&lt;br /&gt;
The bookmark button allows one tap access to bookmarks.  The bookmarks are displayed as a list that can scrolled easily by dragging.&lt;br /&gt;
&lt;br /&gt;
This design assumes that mobile users do not typically have many bookmarks that are organized in folders.&lt;br /&gt;
&lt;br /&gt;
Double-tapping the bookmark icon will add the current page to the list of bookmarks.  This can be done either in the Main Screen, or in the Bookmark screen.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;For discussion:&#039;&#039;&#039;&lt;br /&gt;
* The toolbar at the bottom can show different buttons for bookmark-specific functions such as sorting by name or frequency, display folders, etc.&lt;br /&gt;
* The title bar and URL bar can be removed in this screen to make more room for bookmark items.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
&lt;br /&gt;
=== Tabs Screen ===&lt;br /&gt;
&lt;br /&gt;
[[Image:MobileFF-TouchUI-Tabs.png|frame|Tabs Screen]]&lt;br /&gt;
&lt;br /&gt;
Tapping on the &amp;quot;tabs&amp;quot; button in the Main Screen brings up the Tabs Screen.  This screen displays thumbnails of up to 4 tabs and allows the user to tap and select a tab.&lt;br /&gt;
&lt;br /&gt;
The back and forward buttons in the toolbar can be used to scroll/pan across additional tabs if present.&lt;br /&gt;
&lt;br /&gt;
Tapping on the + icon at the center creates a new tab, and automatically selects it, returning to the Main Screen.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;For discussion:&#039;&#039;&#039; Scroll/Pan can also be done by dragging the screen.  The toolbar can also display a different set of buttons that are more relevant to the tab operations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Comments ====&lt;br /&gt;
&lt;br /&gt;
== Mockup ==&lt;br /&gt;
&lt;br /&gt;
A XUL mockup is available at [[http://wiki.mozilla.org/images/b/b1/Touchscreenbrowser.zip]].  Not all features described above are working, and the XUL/JS code is experimental.&lt;br /&gt;
&lt;br /&gt;
To run the mockup please type:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
firefox -app &amp;lt;path to where its unzipped&amp;gt;/touchscreenbrowser/application.ini&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== To do ===&lt;br /&gt;
&lt;br /&gt;
* Main Screen&lt;br /&gt;
** History chevron in URL box&lt;br /&gt;
** Scrollbars while panning&lt;br /&gt;
** Zoom-to-fit on page load&lt;br /&gt;
*** Is there a simple way to do this?&lt;br /&gt;
* URL Entry Screen&lt;br /&gt;
** Selecting from a hint&lt;br /&gt;
** Scrolling hints via dragging&lt;br /&gt;
** Software keyboard&lt;br /&gt;
** Search button&lt;br /&gt;
* Page Load Screen&lt;br /&gt;
** Progress bar&lt;br /&gt;
* History on Main Screen&lt;br /&gt;
* Bookmark Screen&lt;br /&gt;
* Tabs Screen&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Bugzilla_Talk:Languages&amp;diff=55934</id>
		<title>Bugzilla Talk:Languages</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Bugzilla_Talk:Languages&amp;diff=55934"/>
		<updated>2007-05-03T02:23:23Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: On Python cons&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== On Python cons ==&lt;br /&gt;
&lt;br /&gt;
*  Not having curly-braces on &amp;quot;if&amp;quot; statements and other blocks makes long blocks hard to read.&lt;br /&gt;
** I think this is mostly a red herring. First, you should not write long blocks to begin with. Second, I&#039;ve used Python almost exclusively in a large project for over three years and this has rarely been a problem.&lt;br /&gt;
&lt;br /&gt;
* Poor Unicode handling--strings are ASCII by default, and are Unicode only if you prepend them with u, like u&amp;quot;string&amp;quot;.&lt;br /&gt;
** I think u&amp;quot;&amp;quot; can easily be enforced as a coding policy. Depending on how ambitious your Unicode needs are, Python Unicode may not be enough for you. For Chandler we created PyICU to fix cases where Python&#039;s natural Unicode support falls short.&lt;br /&gt;
&lt;br /&gt;
* No standard way of installing modules like CPAN.&lt;br /&gt;
** There is: Python eggs. These are pretty new, though, so not all projects make eggs or upload them to cheeseshop (equivalent to cpan).&lt;br /&gt;
&lt;br /&gt;
* Python has no equivalent to Perl&#039;s &amp;quot;taint&amp;quot; mode.&lt;br /&gt;
** I know of some attempts at this, and I believe Zope has a sandbox thingy as well, so the situation is probably not as bleak as you think.&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Community:SummerOfCode07:Brainstorming&amp;diff=51956</id>
		<title>Community:SummerOfCode07:Brainstorming</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Community:SummerOfCode07:Brainstorming&amp;diff=51956"/>
		<updated>2007-03-15T17:01:59Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: /* Suggestion List */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Projects with a confirmed mentor and approved by the Mozilla project SoC administrator will be moved to [[Community:SummerOfCode07]]. Potential students should look at that page to find project ideas for which we&#039;d like submissions.&lt;br /&gt;
&lt;br /&gt;
==Ground Rules==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Be specific&#039;&#039;&#039;. It&#039;s hard to understand the impact of, or the size of, vague proposals.&lt;br /&gt;
* &#039;&#039;&#039;Consider size&#039;&#039;&#039;. The student has eight weeks to design, code, test and document the proposal. It needs to fill, but not overfill, that time.&lt;br /&gt;
* &#039;&#039;&#039;Do your research&#039;&#039;&#039;. Support the idea with well-researched links.&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t morph other people&#039;s ideas&#039;&#039;&#039;. If you have a related idea, place it next to the existing one, or add a comment. &lt;br /&gt;
* &#039;&#039;&#039;Insert only your own name into the Mentor column&#039;&#039;&#039;, and then only if you are willing to take on the responsibility. Potential mentors [http://code.google.com/soc/mentor_step1.html sign up here].&lt;br /&gt;
&lt;br /&gt;
([http://weblogs.mozillazine.org/gerv/archives/2006/05/making_a_soc_project_list.html More thoughts on making a good list])&lt;br /&gt;
&lt;br /&gt;
==Suggestion List==&lt;br /&gt;
&lt;br /&gt;
Last year&#039;s ideas: [[Community:SummerOfCode06|General]], [[Thunderbird:Summer_Of_Code_2006|Thunderbird]]&lt;br /&gt;
&lt;br /&gt;
Please use this format for submitting ideas.&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot; valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|- align=&amp;quot;center&amp;quot;&lt;br /&gt;
| style=&amp;quot;background-color: #efefef;&amp;quot; | &#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;background-color: #efefef;&amp;quot; | &#039;&#039;&#039;Abstract - links to details/bugs/etc&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;background-color: #efefef;&amp;quot; | &#039;&#039;&#039;Reporter&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;background-color: #efefef;&amp;quot; | &#039;&#039;&#039;Mentor(s)&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;background-color: #efefef;&amp;quot; | &#039;&#039;&#039;Comments&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | JPEG 2000&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | [https://bugzilla.mozilla.org/show_bug.cgi?id=36351 Add JPEG 2000 support to Mozilla]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Camino: Tabspose&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Expose for tabs, but in the browser window ({{bug|312007}})&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | pinkerton&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | pinkerton&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | I&#039;ve wanted to do this for years...&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Make SeaMonkey Not Suck As A News Reader&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Basically, get some traction on some of the highlights of {{bug|176238}}/{{bug|12699}} , in particular: &amp;quot;clickable references&amp;quot; ({{bug|62033}}) and headers in general ({{bug|23114}}), a more usable subscribe dialog ({{bug|40260}}), reordering of the folder pane ({{bug|150274}}, maybe even hierarchical?). For bonus points, a correct implementation of the nntp/news protocols ({{bug|89939}}) would be really cool!&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Mnyromyr&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Mnyromyr&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | UI stuff would be for SeaMonkey, but should be portable to Thunderbird easily. Both would profit from backend fixes.&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Real Mail Templates&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Currently, mail templates are too static, their interaction with mails you respond to etc. is almost zero ({{bug|21210}}, {{bug|107876}} and others). It would be an enourmous progress if we could have variables like $$EMailAddress$$, $$QuotedBody$$, $$Date$$, $$CustomVariable(with Parameter)$$ in a template which get filled in when replying or composing.&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Mnyromyr&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Mnyromyr&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | UI stuff would be for SeaMonkey, but should be portable to Thunderbird easily. Both would profit from backend fixes.&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Score Filter&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | A score filter ({{bug|151622}}) would associate an integer with every message. This integer could then be changed by filter actions like &amp;quot;Increase by x&amp;quot;, &amp;quot;Set to Y&amp;quot;, etc. and have itself filter criteria like &amp;quot;If score is lower than A&amp;quot;, &amp;quot;If score has value B&amp;quot;, etc. Several other message properties alterable by filter actions (like isJunk or isThread) would need to be made usable as filter criteria for that for full points. In toto, this would allow for very fine-grained message control.&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Mnyromyr&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Mnyromyr&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | UI stuff would be for SeaMonkey, but should be portable to Thunderbird easily. Both would profit from backend fixes.&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Metalink&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | A simple XML format for downloads ({{bug|331979}}) that lists mirrors and checksums, along with other useful metadata such as mirror location. Listing multiple URLs for a file increases availability while the checksums guarantee integrity and let downloads be repaired automatically. You can also filter downloads by location and other things. This is currently supported by over ten download managers.&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Antini&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Auto verify MD5/SHA1 hashes &amp;amp; PGP signatures&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | Automatically verifying MD5/SHA1 hashes, and optionally PGP signatures, of downloads. When you have downloaded a file, the download manager should try to download filename.md5, filename.sha, filename.asc and run the associated tool on the downloaded file to verify. Mark the entry as red or something in the download manager, and change the Open link to Info link, if the file did not verify. The Info link would open a page explaining what is wrong. It could perhaps have a open or preferably just delete file button. More difficult case would be to get the md5/sha1 signature if it is just embedded on the page where the download link is, but you could try some heuristics... (see also bug 292481).&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | HeikkiToivonen&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | PGP signature support would probably be easiest to build on top of Enigmail extension.&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Cross_Site_XMLHttpRequest&amp;diff=49605</id>
		<title>Cross Site XMLHttpRequest</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Cross_Site_XMLHttpRequest&amp;diff=49605"/>
		<updated>2007-02-21T00:32:34Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: /* Details */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Cross-Site XMLHttpRequest allows a web page to read information from other web servers using norm XMLHttpRequest. In the past this has not been permitted since the other server may be sitting inside a corporate firewall or may be a server where the user is logged in.&lt;br /&gt;
&lt;br /&gt;
To solve this problem it is suggested that the accessed server can signal back to the browser that it is ok for other sites to access certain pages on the server. Firefox checks for this and only returns the response to the page if the server explicitly allows it. Otherwise the browser will throw away the response from the server and throw an exception.&lt;br /&gt;
&lt;br /&gt;
== Details ==&lt;br /&gt;
&lt;br /&gt;
There are currently two draft specs from w3c for how this should work. The signaling for when a document is accessible is spec&#039;ed in the access-control draft spec [http://www.w3.org/TR/access-control/]. This states that the site can insert &amp;lt;?access-control?&amp;gt; processing instructions into XML files that says which sites can access the file. It also allows for http-headers to be added to allow access to be controlled to any file type.&lt;br /&gt;
&lt;br /&gt;
The PI contains lists of URL patterns that describe which URLs can access the file. These patterns can contain wildcards, but follow strict parsing rules rather than being general URLs.&lt;br /&gt;
&lt;br /&gt;
Additionally [http://lists.w3.org/Archives/Public/public-webapi/2006Jun/0012] is a draft spec for how XMLHttpRequest should interact with the access-control spec. This spec describes some headers that should be included when making a cross site request. (Though I personally wonder if this part should be moved into the access-control spec.) It also describes how to deal with http methods other than GET and POST.&lt;br /&gt;
&lt;br /&gt;
What about [http://lxr.mozilla.org/mozilla/source/extensions/webservices/docs/New_Security_Model.html]?&lt;br /&gt;
&lt;br /&gt;
== Suggested Implementation ==&lt;br /&gt;
&lt;br /&gt;
A goal of the implementation is that it should be reusable for other things than XMLHttpRequest. For example document.load should be able to do the same cross-site loads with the same restrictions. As should XSLT and XBL.&lt;br /&gt;
&lt;br /&gt;
To do this we&#039;ll set up an [http://lxr.mozilla.org/mozilla/source/netwerk/base/public/nsIStreamListener.idl nsIStreamListener] that sits between the normal nsIStreamListener and the [http://lxr.mozilla.org/mozilla/source/netwerk/base/public/nsIChannel.idl nsIChannel]. Once onStartRequest is called we check for access control headers. If the headers deny access we cancel the channel with a network error failure. If headers allow access we pass through all calls to the outer caller.&lt;br /&gt;
&lt;br /&gt;
If headers don&#039;t say either way and the content type is an XML one (do we have a good way to determine that?) we set up a parser and ourselfs as sink. We&#039;ll then listen to notifications until the first start-element notification. At the same time we have to store all incoming data that is fed to the parser. If the access control PIs doesn&#039;t indicate that access should be granted we cancel the channel.&lt;br /&gt;
&lt;br /&gt;
If access control is granted we forward calls to the outer caller and stream the buffered data to it.&lt;br /&gt;
&lt;br /&gt;
=== Issues ===&lt;br /&gt;
&lt;br /&gt;
* We have to check that the code in onStartRequest in the original streamlistener doesn&#039;t do things that are too late to do once the delayed onStartRequest is called.&lt;br /&gt;
&lt;br /&gt;
* Is it possible to cancel with a network error if we get a 404 or 401 or similar? This would be a good way to avoid making it possible for the site to check for the existence of files on the server or check if the user is logged in or not.&lt;br /&gt;
&lt;br /&gt;
== Security worries ==&lt;br /&gt;
&lt;br /&gt;
* The first thing that worries me is that you can make POST submissions to any url and include XML data as payload. It is already possible to make POST submissions to any url, but the only possible payload is plain/text encoded form data or multipart/mixed encoded files and form data. With Cross-Site XMLHttpRequest it would be possible to send XML data. In particular there is worry that this would make it possible to do SOAP requests to any server. Note that while the page would be unable to access the data returned by the SOAP request, that isn&#039;t necessary if the request itself is &amp;quot;transfer all users money to account 12345-67&amp;quot;. To avoid this we could either use the model as for non-GET-non-POST requests defined in the XHR spec [http://lists.w3.org/Archives/Public/public-webapi/2006Jun/0012], or we could use something like [http://lxr.mozilla.org/mozilla/source/extensions/webservices/docs/New_Security_Model.html]&lt;br /&gt;
&lt;br /&gt;
* Should we try to follow these specs even when accessing files on the same domain? From the sites point of view they can&#039;t rely on that anyway since all browsers don&#039;t support the access-control spec (and old versions never will).&lt;br /&gt;
&lt;br /&gt;
* We have to make sure to not notify the onreadystatechange listener or any other listeners until we&#039;ve done all access control checks. Otherwise it would be possible to check for the availability of files on other servers though you couldn&#039;t actually read the content.&lt;br /&gt;
&lt;br /&gt;
* We have to make sure to not put data in .responseText until we&#039;ve passed access control checks even for XML files.&lt;br /&gt;
&lt;br /&gt;
* We have to make it impossible to distinguish between a access-control-failed error and network errors such as 404s. Can the implementation &amp;quot;recancel&amp;quot; a canceled channel?&lt;br /&gt;
&lt;br /&gt;
* Should we check for PIs even if HTTP headers has said that access is granted? It&#039;ll always be possible to circumvent those headers using .mimetypeOverride which&#039;ll make us not treat the doc as XML and thus we won&#039;t even look for PIs. Alternatively we could ignore the .mimetypeOverride when checking for PIs but that might be a problem with poorly configured servers (which is the whole reason for .mimetypeOverride)&lt;br /&gt;
&lt;br /&gt;
* We should make sure to make it impossible to set authentication headers since that would make it easier for a site to attempt (distributed) brute force hacking against authenticated servers. Note though that such hacking would be significantly complicated by the fact that the server must be password protected but still have files that it grants access to a 3rd party server, which doesn&#039;t really make a lot of sense.&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Community:SummerOfCode06&amp;diff=24213</id>
		<title>Community:SummerOfCode06</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Community:SummerOfCode06&amp;diff=24213"/>
		<updated>2006-04-18T23:50:48Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Add your ideas here for Projects for the Google [http://code.google.com/summerofcode.html Summer of Code 2006]&lt;br /&gt;
&lt;br /&gt;
We will be reviewing ideas posted here the week of 4/17 and putting together proposals the following week.  Please note if you are interested in being a Mentor for one of these projects, or suggest someoneone who could serve as mentor.  Mentor requirements are here - http://code.google.com/soc/mentorfaq.html&lt;br /&gt;
&lt;br /&gt;
Thanks&lt;br /&gt;
&lt;br /&gt;
Chris Hofmann&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
- Complete Torrent-Integration: [http://firepuddle.mozdev.org/] (started in last year&#039;s SoC)&lt;br /&gt;
&lt;br /&gt;
- Complete Skype-Integration for Thunderbird (started in last year&#039;s SoC)&lt;br /&gt;
&lt;br /&gt;
- Work on Venkman to bring it some good updates/bugfixes/new features. Maybe work to do a 1.0 release? (https://bugzilla.mozilla.org/show_bug.cgi?id=141097)&lt;br /&gt;
&lt;br /&gt;
- XUL editor plugin for [http://www.eclipse.org Eclipse] that leverages the XULRunner component and JS debugger from the [http://www.alphaworks.ibm.com/tech/ajaxtk Eclipse Ajax Toolkit Framework] to create a XUL UI development tool. ([[User:Beltzner|Beltzner]] 09:31, 17 April 2006 (PDT))&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;Advance the XUL platform&amp;quot; projects (to be defined) e.g. implement &amp;lt;menugroup&amp;gt;, &lt;br /&gt;
fix menu bugs, etc. [[User:Ben|Ben]] 10:38, 17 April 2006 (PDT)&lt;br /&gt;
&lt;br /&gt;
- Multi-threaded (accelerated) Download Manager &lt;br /&gt;
([https://bugzilla.mozilla.org/show_bug.cgi?id=40106]) with possible [http://www.metalinker.org Metalink] (Mirrors/P2P/checksums) support.&lt;br /&gt;
&lt;br /&gt;
- Automatically verifying MD5/SHA1 hashes, and optionally PGP signatures, of downloads. When you have downloaded a file, the download manager should try to download filename.md5, filename.sha, filename.asc and run the associated tool on the downloaded file to verify. Mark the entry as red or something in the download manager, and change the Open link to Info link, if the file did not verify. The Info link would open a page explaining what is wrong. It could perhaps have a open or preferably just delete file button. More difficult case would be to get the md5/sha1 signature if it is just embedded on the page where the download link is, but you could try some heuristics...&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Community:SummerOfCode06&amp;diff=24212</id>
		<title>Community:SummerOfCode06</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Community:SummerOfCode06&amp;diff=24212"/>
		<updated>2006-04-18T23:49:16Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: Verify downloads&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Add your ideas here for Projects for the Google [http://code.google.com/summerofcode.html Summer of Code 2006]&lt;br /&gt;
&lt;br /&gt;
We will be reviewing ideas posted here the week of 4/17 and putting together proposals the following week.  Please note if you are interested in being a Mentor for one of these projects, or suggest someoneone who could serve as mentor.  Mentor requirements are here - http://code.google.com/soc/mentorfaq.html&lt;br /&gt;
&lt;br /&gt;
Thanks&lt;br /&gt;
&lt;br /&gt;
Chris Hofmann&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
- Complete Torrent-Integration: [http://firepuddle.mozdev.org/] (started in last year&#039;s SoC)&lt;br /&gt;
&lt;br /&gt;
- Complete Skype-Integration for Thunderbird (started in last year&#039;s SoC)&lt;br /&gt;
&lt;br /&gt;
- Work on Venkman to bring it some good updates/bugfixes/new features. Maybe work to do a 1.0 release? (https://bugzilla.mozilla.org/show_bug.cgi?id=141097)&lt;br /&gt;
&lt;br /&gt;
- XUL editor plugin for [http://www.eclipse.org Eclipse] that leverages the XULRunner component and JS debugger from the [http://www.alphaworks.ibm.com/tech/ajaxtk Eclipse Ajax Toolkit Framework] to create a XUL UI development tool. ([[User:Beltzner|Beltzner]] 09:31, 17 April 2006 (PDT))&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;Advance the XUL platform&amp;quot; projects (to be defined) e.g. implement &amp;lt;menugroup&amp;gt;, &lt;br /&gt;
fix menu bugs, etc. [[User:Ben|Ben]] 10:38, 17 April 2006 (PDT)&lt;br /&gt;
&lt;br /&gt;
- Multi-threaded (accelerated) Download Manager &lt;br /&gt;
([https://bugzilla.mozilla.org/show_bug.cgi?id=40106]) with possible [http://www.metalinker.org Metalink] (Mirrors/P2P/checksums) support.&lt;br /&gt;
&lt;br /&gt;
- Automatically verifying MD5/SHA1 hashes, and optionally PGP signatures, of downloads. When you have downloaded a file, the download manager should try to download filename.md5, filename.sha, filename.asc and run the associated tool on the downloaded file to verify. Mark the entry as red or something in the download manager, and change the Open link to Info link. The Info link would open a page explaining what is wrong. It could perhaps have a open or preferably just delete file button. More difficult case would be to get the md5/sha1 signature if it is just embedded on the page where the download link is, but you could try some heuristics...&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Necko:SSL_v2_Sites&amp;diff=8377</id>
		<title>Necko:SSL v2 Sites</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Necko:SSL_v2_Sites&amp;diff=8377"/>
		<updated>2005-05-21T04:36:23Z</updated>

		<summary type="html">&lt;p&gt;HeikkiToivonen: low cipher section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is a list of websites known to only support SSL v2 - that is, if you turn it off, you get an error message saying that you can&#039;t access the site, or any attempt to connect to the site causes a long hang. In order for a site to be added to this list, it should be quickly accessible with SSL v2 enabled, but you should get an error message or a hang with SSL v2 disabled.&lt;br /&gt;
&lt;br /&gt;
We may later attempt to contact and evangelise these sites, but at the moment this is merely a recording exercise.&lt;br /&gt;
&lt;br /&gt;
* [https://webmail.komtel.net/horde/imp/ https://webmail.komtel.net/horde/imp/]&lt;br /&gt;
* [https://gnunet.org/drupal/?q=node/61 https://gnunet.org/drupal/?q=node/61]&lt;br /&gt;
* [https://www.umsu.de/ https://www.umsu.de/] and friends at 1&amp;amp;1, e.g.:&lt;br /&gt;
** [https://www.pro-regenwald.de/ https://www.pro-regenwald.de/]&lt;br /&gt;
* [https://register.btinternet.com/ https://register.btinternet.com/]&lt;br /&gt;
* [http://www.cpucityshop.co.uk/ http://www.cpucityshop.co.uk/]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Not SSL v2 but low security ciphers (other places to discuss these?):&lt;br /&gt;
&lt;br /&gt;
* [http://www.comcastsupport.com/sdcxuser/lachat/user/userchatstart.asp http://www.comcastsupport.com/sdcxuser/lachat/user/userchatstart.asp]&lt;br /&gt;
** I have disabled SSL v2, all SSL v2 ciphers, everything with less than 128 bits, MD5 and this is the only site in over a year that I have seen that does not work.&lt;br /&gt;
&lt;br /&gt;
Other useful links:&lt;br /&gt;
&lt;br /&gt;
* [http://weblogs.mozillazine.org/gerv/archives/008157.html Gerv&#039;s original blog post]&lt;br /&gt;
* [http://my.opera.com/forums/showthread.php?s=83e643b69072bab8644e3553610305c0&amp;amp;threadid=91417 Opera forum post]&lt;br /&gt;
* [http://www.netcraft.com Netcraft] may have SSL v2 server prevalence info&lt;br /&gt;
* [http://www.securityspace.com/s_survey/sdata/200504/protciph.html SecuritySpace] has another survey, although I don&#039;t think they have figures for SSL v2 &amp;lt;b&amp;gt;only&amp;lt;/b&amp;gt;.&lt;/div&gt;</summary>
		<author><name>HeikkiToivonen</name></author>
	</entry>
</feed>