Ecosyste.ms: Timeline
Browse the timeline of events for every public repo on GitHub. Data updated hourly from GH Archive.
RohanGhalib created a comment on an issue on RohanGhalib/publicnotepad
sorry, forgot to add sanitization in comments, it think i should strip html tags althogether coz rich text isnt necessary in comments
RohanGhalib created a comment on an issue on RohanGhalib/publicnotepad
done! Pushing just now
RohanGhalib closed an issue on RohanGhalib/publicnotepad
Security issue
Would contact you privately, but considering that this issue has been _very_ much abused I don't think it matters now 😅 https://github.com/RohanGhalib/publicnotepad/blob/10d6a7a6abb75db25732f3f...RohanGhalib created a comment on an issue on RohanGhalib/publicnotepad
Right! i have added html sanitization so its no longer possible to add legacy html tags apart from those used in rich text formatting
RohanGhalib closed an issue on RohanGhalib/publicnotepad
javascript injection
It's possible to add notes with arbitrary HTML which can run potentially unsafe scripts. For example, [this note I made](https://rohanghalib.me/publicnotepad/view_note.php?id=82) runs `alert(locati...RohanGhalib pushed 1 commit to main RohanGhalib/publicnotepad
- fixed javascript injection Co-Authored-By: Mahad Kalam <[email protected]> 1d0fad8