Alright, so here's what we're thinking. We'd change virtuals to always create their handler closures as trusted as long as the virtual was created during the secure part of the load process (is part of the stock UI). This should mean the mouse enter on the inventory slot is created as secure even if an addon causes the control to be created and that should prevent the tainting issue.
|