(This is a spin-off of a discussion in #2266, also raised during the discussion with @GJFR at the EPUB meeting; raising it as a separate issue for a better tracking)
At the moment, the only reference to file: URLs in the spec is a SHOULD NOT for the href attribute in the package file. These urls are obvious security issues for content documents that are supposed to be 'installed' in various places, and there is no reason to use them. The proposal is to explicitly disallow their usage in EPUB.
(This is a spin-off of a discussion in #2266, also raised during the discussion with @GJFR at the EPUB meeting; raising it as a separate issue for a better tracking)
At the moment, the only reference to file: URLs in the spec is a SHOULD NOT for the
hrefattribute in the package file. These urls are obvious security issues for content documents that are supposed to be 'installed' in various places, and there is no reason to use them. The proposal is to explicitly disallow their usage in EPUB.