From cd79e33eb4c40fe42ee59bcbc0e04cf80b618f2a Mon Sep 17 00:00:00 2001 From: "dbaron%dbaron.org" Date: Mon, 15 Mar 2004 22:28:41 +0000 Subject: [PATCH] Prevent a label's for content from being another label (or itself), which can lead to crashes. b=237357 Patch from Rene Pronk . sr=dbaron r=jst a=chofmann git-svn-id: svn://10.0.0.236/trunk@153992 18797224-902f-48f8-a5cc-f745e15eee43 --- .../content/html/content/src/nsHTMLLabelElement.cpp | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/mozilla/content/html/content/src/nsHTMLLabelElement.cpp b/mozilla/content/html/content/src/nsHTMLLabelElement.cpp index 9e8db26fa97..6ee445bf5ad 100644 --- a/mozilla/content/html/content/src/nsHTMLLabelElement.cpp +++ b/mozilla/content/html/content/src/nsHTMLLabelElement.cpp @@ -359,6 +359,12 @@ nsHTMLLabelElement::UnsetAttr(PRInt32 aNameSpaceID, nsIAtom* aAttribute, return nsGenericHTMLElement::UnsetAttr(aNameSpaceID, aAttribute, aNotify); } +inline PRBool IsNonLabelFormControl(nsIContent *aContent) +{ + return aContent->IsContentOfType(nsIContent::eHTML_FORM_CONTROL) && + aContent->Tag() != nsHTMLAtoms::label; +} + already_AddRefed nsHTMLLabelElement::GetForContent() { @@ -377,7 +383,7 @@ nsHTMLLabelElement::GetForContent() nsIContent *result = nsnull; if (domElement) { CallQueryInterface(domElement, &result); - if (result && !result->IsContentOfType(nsIContent::eHTML_FORM_CONTROL)) { + if (result && !IsNonLabelFormControl(result)) { NS_RELEASE(result); // assigns null } } @@ -399,7 +405,7 @@ nsHTMLLabelElement::GetFirstFormControl(nsIContent *current) for (PRUint32 i = 0; i < numNodes; i++) { nsIContent *child = current->GetChildAt(i); if (child) { - if (child->IsContentOfType(nsIContent::eHTML_FORM_CONTROL)) { + if (IsNonLabelFormControl(child)) { NS_ADDREF(child); return child; }