Jonathan's profileDesign by CommitteePhotosBlogLists Tools Help

Blog


    November 16

    Getting rid of the security warning on the default XML stylesheet

    With a recent update to IE (not sure if it was IE7 or earlier), browsing to an XML file without a stylesheet on a local drive now gives a security warning.  The cause of this is the little bit of script generated by the default stylesheet to make the + and - collapsing behavior work.  Of course, for IE to warn it's users against script that it ships itself seems rather kookoo, let's hope they fix this oversight soon.

    You can "Click here for options..." including allowing the script to run, but honestly that's just too much work when you just want a quick view of the XML.  At the WSDL 2.0 Interop Event, others were complaining about this behavior too, and wondered how to turn it off globally.  So I got around to looking for a method.

    What I found is in the Advanced tab of Internet Options - the "Allow active content to run in files on My Computer" option.  By selecting this option, clicking OK, and then closing all your browser windows, you can open local XML files without the annoying warning.

    Of course, this is a pretty lame workaround, because not only allowing IE access to it's own internal organs, so to speak, this option also has the potential to allow real security violations - such as attacks that might run by tricking the user to download a web page to their local drive and then open it from there - the useful warnings against Active content might be quite valuable.

    Let's hope IE get's a little smarter about detecting what's harmful and what's not. 

    Comments

    Please wait...
    Sorry, the comment you entered is too long. Please shorten it.
    You didn't enter anything. Please try again.
    Sorry, we can't add your comment right now. Please try again later.
    To add a comment, you need permission from your parent. Ask for permission
    Your parent has turned off comments.
    Sorry, we can't delete your comment right now. Please try again later.
    You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
    Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
    Complete the security check below to finish leaving your comment.
    The characters you type in the security check must match the characters in the picture or audio.
    Jonathan Marsh has turned off comments on this page.

    Trackbacks

    Weblogs that reference this entry
    • None