GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Stefan Bohacek (stefan@stefanbohacek.online)'s status on Sunday, 15-Sep-2024 20:11:16 JST Stefan Bohacek Stefan Bohacek

    So an interesting change is coming to Mastodon embeds.

    Previously, the embed code consisted of an iframe, going forward, this is being switched to a blockquote.

    In either case, the original text of the post is not included and is rather added after the main page the embed is on is loaded.

    https://github.com/mastodon/mastodon/pull/31766

    #mastodon #embeds #fediverse

    In conversation about 9 months ago from stefanbohacek.online permalink

    Attachments


    1. https://sbonline.nyc3.digitaloceanspaces.com/media_attachments/files/113/132/773/964/975/464/original/eb8a944ccc211e81.png

    • Embed this notice
      qwazix (qwazix@bananachips.club)'s status on Sunday, 15-Sep-2024 20:11:12 JST qwazix qwazix
      in reply to

      @stefan now that I think about it, with instances coming and going, this is a security issue. I can go buy a domain of a defunct instance and XSS all sites that ever embedded a post.

      In conversation about 9 months ago permalink
      gidi likes this.
    • Embed this notice
      Stefan Bohacek (stefan@stefanbohacek.online)'s status on Sunday, 15-Sep-2024 20:11:13 JST Stefan Bohacek Stefan Bohacek
      in reply to

      For comparison, the previous (and on most Mastodon servers, the current) version looked like this.

      In conversation about 9 months ago permalink

      Attachments


      1. https://sbonline.nyc3.digitaloceanspaces.com/media_attachments/files/113/132/863/806/489/485/original/2602ae458d450a23.png
    • Embed this notice
      qwazix (qwazix@bananachips.club)'s status on Sunday, 15-Sep-2024 20:11:13 JST qwazix qwazix
      in reply to

      @stefan it seems presumptive to my old webdev mind to assume all places that allow embeds will allow external js.

      Also, seriously, do you expect me to backdoor my own site??

      In conversation about 9 months ago permalink
      gidi repeated this.
    • Embed this notice
      Stefan Bohacek (stefan@stefanbohacek.online)'s status on Sunday, 15-Sep-2024 20:11:14 JST Stefan Bohacek Stefan Bohacek
      in reply to

      Okay, looking at the new embed code more closely, this is...something else.

      In conversation about 9 months ago permalink

      Attachments


      1. https://sbonline.nyc3.digitaloceanspaces.com/media_attachments/files/113/132/823/857/611/913/original/c69aef09d11e1699.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.