7 ms·
Be careful of most JavaScript markdown implementations! Their live preview (showdown-based) JS has XSS holes. Their ruby version seems to much better! Perhap
by anotherjesse 17y ago
Be careful of most JavaScript markdown implementations! Their live preview (showdown-based) JS has XSS holes.
Their ruby version seems to much better!
Perhaps it should be renamed "developer markdown" - DMD - and then github/stackoverflow/... should all have a standard markdown fork?
Also having a standard test suite that tests for XSS and other holes would be nice :)
- kneath 17y agoThe only XSS vulnerability in the code is the ability to XSS yourself, which you can do with any browser with a javascript console. Unless of course you're using Javascript to parse user generated markdown instead of doing it server-side, which is just silly. Markdown is a formatting language, not a method to protect against XSS. It belongs in a different tier of your code.
- anotherjesse 17y agoIf you were to take the GFM that was implemented on top of showdown and use it for something like a wiki (ala stackoverflow's wiki-fication of questions), then currently you have XSS holes. I love GFM. I've been using it on userscripts.org for months. But the JS version at http://github.github.com/github-flavored-markdown/preview.html http://github.github.com/github-flavored-markdown/preview.ht... has holes that their ruby version does not have - http://github.com/mojombo/github-flavored-markdown/issues/#issue/1 http://github.com/mojombo/github-flavored-markdown/issues/#i...