ಟ್ವೀಟ್ಗಳು ಮತ್ತು ಪ್ರತಿಕ್ರಿಯೆಗಳು
- ಟ್ವೀಟ್ಗಳು
- ಟ್ವೀಟ್ಗಳು & ಪ್ರತಿಕ್ರಿಯೆಗಳು
- ಮಾಧ್ಯಮ
@slekies ತಡೆಹಿಡಿಯಲಾಗಿದೆ
ನೀವು ಖಚಿತವಾಗಿಯೂ ಈ ಟ್ವೀಟ್ಗಳನ್ನು ನೋಡಲು ಬಯಸುವಿರಾ? ಟ್ವೀಟ್ಗಳನ್ನು ನೋಡುವುದು @slekies ಅವರನ್ನು ತಡೆತೆರವುಗೊಳಿಸುವುದಿಲ್ಲ.
-
Patrick Toomey ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@patricktoomey@arturjanc@sirdarckcat@mikewest legacy is not the point that I am trying to make. Twitter sucks for these discussions. -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@sirdarckcat@mikewest again:I am not saying we can't do this.I am not at all oposing the idea. Just saying we need to be careful -
@arturjanc@sirdarckcat@mikewest just wanted to add one data point to the discussion and not oppose the general idea. -
@arturjanc@sirdarckcat@mikewest and I am saying that not all ways will as seen with the many hacks due to innerHTML. -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@sirdarckcat@mikewest No, I am saying we should harden in a way that FWs play nicely with it. -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@sirdarckcat@mikewest yes, definetly. I am the last one to argue against hardening. Just brought up one important issue. -
@arturjanc@sirdarckcat@mikewest and it is not easy to fix ;-). -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@sirdarckcat@mikewest not only strict-dynamic, also unsafe-eval, which is required for most frameworks. -
@arturjanc@sirdarckcat@mikewest every single one is a CSP bypass btw -
@arturjanc@sirdarckcat@mikewest then we should choose a hardening way that will not lead to these hacks -
@arturjanc@sirdarckcat@mikewest we should look at them to understand why these hacks are in place. -
@arturjanc@sirdarckcat@mikewest I can show you dozens of examples where the current behavior of innerHTML led to hacks in libraries. -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@sirdarckcat@mikewest I am not saying that at all. Just saying we need to take this into account to not get it wrong. -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@sirdarckcat@mikewest I was thinking more about the default behavior. But if security is inconvenient, no one will adopt it. -
@arturjanc@mikewest these hacks are also not introduced against the devs intend, but for the opposite. -
Artur Janc ಗೆ ಪ್ರತ್ಯುತ್ತರವಾಗಿ
@arturjanc@mikewest if the API does not fullfill the needs, devs will hack around it. Also innerHTML is not a safe, hardened API. -
@mikewest I can show you a few PoCs next time we meet. -
@mikewest if you want to strengthen CSP allow scripts in innerHTML and libraries will not implement insecure code for not surprising devs. -
@mikewest that's why jquery and other libraries have magic html() methods to replace innerHTML with a function that also executes scripts. -
@mikewest devs expect that inner_HTML_ executes all of HTML and not just a subset.
ಲೋಡಿಂಗ್ ಸಮಯ ಸ್ವಲ್ಪ ತೆಗೆದುಕೊಳ್ಳುತ್ತಿರುವಂತೆನಿಸುತ್ತದೆ.
Twitter ಸಾಮರ್ಥ್ಯ ಮೀರಿರಬಹುದು ಅಥವಾ ಕ್ಷಣಿಕವಾದ ತೊಂದರೆಯನ್ನು ಅನುಭವಿಸುತ್ತಿರಬಹುದು. ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಹೆಚ್ಚಿನ ಮಾಹಿತಿಗೆ Twitter ಸ್ಥಿತಿಗೆ ಭೇಟಿ ನೀಡಿ.
Sebastian Lekies