create new tag
, view all tags

Bug: Any embeddable html object is executed.

This is one of those things that is a feature as much as it is a bug. However it is submitted as a bug report to catch the eyes of those who are scanning for potential risks. Maybe we should have a new category for things like this: RiskyFeatures ?

The highest profile subset of this "embed anthing" risk/feature is javascript: UsersCanPutJavascriptInTopics.

-- MattWilkie - 29 Nov 2004

While battling trying to get JSCaleandar to work I found not only could I embed the javascript in the body of a topic, I could also enbed the <LINK CSS> in the body &emdash; I didn't have to put it in the header.

This may be the browser being iberal in its interpretation, but it worked.

(OK, I admit it, I used <!--  LINK --> to hide it)

-- AntonAylward - 27 Nov 2004

Topic revision: r1 - 2004-11-29 - MattWilkie
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2018 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.