Skip to content
This repository has been archived by the owner on May 11, 2023. It is now read-only.

Add query parameter to restrict origin #1

Merged
merged 3 commits into from
Apr 25, 2018
Merged

Add query parameter to restrict origin #1

merged 3 commits into from
Apr 25, 2018

Conversation

dbkr
Copy link
Member

@dbkr dbkr commented Apr 24, 2018

No description provided.

@ara4n
Copy link
Member

ara4n commented Apr 24, 2018

lgtm. whilst you're in there, perhaps put a comment to explain wtf this file is and what's going on, and link to the synapse instructions of how to host your own, and perhaps the github issue for getting rid of it?

and an explanatory comment to the file itself
README.md Outdated
@@ -4,16 +4,10 @@ UserContent
A way to render user generated content with a different origin to the main application.
This can be used to avoid XSS attacks.

Version 1
---------
This is used by Riot to display content in end-to-end encrypted chats. See
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"to display the download button for encrypted attachments" perhaps?

v1.html Outdated
attachments into their own origin, away from your Riot. See
https://github.com/matrix-org/usercontent/blob/master/README.md
for more info, or https://github.com/vector-im/riot-web/blob/master/README.md#configjson
if you'd like to host your own.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

let's add a link to bug 6173 so people can track progress on replacing it with iframes

@dbkr
Copy link
Member Author

dbkr commented Apr 24, 2018

@ara4n PTAL

@dbkr dbkr merged commit d32daa6 into master Apr 25, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants