Jason Nichols
Jason Nichols

Reputation: 3760

Is it possible to nest one data: URI inside another?

If I use a data URI to construct a src attribute for an HTML element, can it in turn have another data URI inside it?

I know you can't use data uri's for iframes (I'm actually trying to construct an OSDX document and pass it to the browser with an icon encoded in base64 but that's a really niche use case and this is more of a general question), but assuming you could, my use case would look like:

var iframe = document.createElement('iframe');
var icon = document.createElement('image');
var iSrc = '*[REALLY LONG STRING]*/';
iframe.src='data:text/html,<html><body><image src="'+iSrc+'" /></body</html>
document.body.appendChild(iframe);

Basically what I'm after is is there anything in a data uri that would break a parent data uri?

Upvotes: 4

Views: 548

Answers (2)

Jason Nichols
Jason Nichols

Reputation: 3760

Yes you can. I really thought it was impossible, as did everyone I asked.

Example:
Pasting the following into your browser's URL bar should render a gmail logo in an html page that says hello world.

data:text/html,<html><body><p>hello world</p><img src="" /></body></html>

or for a shorter example courtesy of Pumbaa80:

data:text/html,<script src="data:text/javascript,alert('hello world')"></script>

Upvotes: 6

admdrew
admdrew

Reputation: 3863

MSDN explicitly supports this:

Data URIs can be nested.

An old blog entry talks a little bit more about embedding images within CSS using data: :

Neither dataURI spec nor any other mentions if dataURI’es can not be nested. So here’s the testcase where dataURI’ed CSS has dataURI’ed image embedded. IE8b1, Firefox3 and Safari applied the stylesheet and showed the image, Opera9.50 (build 9613) applies the stylesheet but doesn’t show the embedded image! So it seems that Opera9 doesn’t expect to get anything embedded inside of an already embedded resource! :D

But funny thing, as IE8b1 supports expressions and also supports nested data URI’es, it has the same potential security flaw as Firefox does (as described in the section above). See the testcase — embedded CSS has the following code: body { background: expression(a()); } which calls function a() defined in the javascript of the main page, and this function is called every time the expression is reevaluated. Though IE8b1 has limited expressions support (which is going to be explained in a separate post) you can’t use any code as the expression value, but you can only call already defined functions or use direct string values. So in order to exploit this feature we need to have a ready javascript function already located on the page and then we can just call it from the expression embedded in the stylesheet. That’s not very trivial obviously, but if you have a website that allows people to specify their own stylesheets and you want to be on the safe side, you have to either make sure you don’t have a javascript function that can cause any potential harm or filter expressions from people’s stylesheets.

Upvotes: 2

Related Questions