E-mail List Archives

Re: aria-expanded state for show-hide interaction?

for

From: Mallory van Achterberg
Date: Nov 24, 2014 4:24AM


On Sun, Nov 23, 2014 at 05:37:48PM -0500, Birkir R. Gunnarsson wrote:
> <input type="hidden" value="AlreadyDone"> <!-- this should be hidden
> still, I thought -->

I thought so as well. Type=hidden is supposed to always be hidden,
from all user agent users, at all times. That was the point of the
type, I thought.

Would be an issue if some users, due to some author's misuse of
aria-hidden, would start seeing CSRF tokens and other submitty
information.

_mallory