3 ms·
Yea, that's totally true. I would recommend using an origin property to be used every time an instance of the Library is created. Please refer: https://github.c
by softvar 10y ago
Yea, that's totally true.
I would recommend using an origin property to be used every time an instance of the Library is created. Please refer: https://github.com/wingify/across-tabs#usage https://github.com/wingify/across-tabs#usage
- detaro 10y agoThen don't have a default that works without doing so. Really, defaults like this lead to "works, ship it" and totally unnecessary cases of vulnerable software.
- Karupan 10y agoSecond this. A lot of developers will just drop it in without reading the caveats. Just make the origin a mandatory parameter.
- softvar 10y agoDoes that mean, the library should not act when an origin is not specified and throw some kinda message in the console?
- tokenizerrr 10y agoYes, a required argument. It's not uncommon. Think API keys.
- fdim 10y agoReminds me mongodb being open/unprotected by default, that turned out well...
- deadbunny 10y agoDon't use unsafe defaults ffs, that's how things get exploited.
- softvar 10y agoDoes that mean, the library should not act when an origin is not specified and throw some kinda message in the console? How can it be enforced? Any suggestions? Users can also make it a bit more complicated while using `*` to get hacked by accepting responses which match some kinda pattern(it's not bullet-proof though) and simply discarding others.
- cryptarch 10y agoPut the wildcard functionality behind a setter with a long name and make the default the current domain?
- Bartkusa 10y agoPut it behind a setter with "doNotUseOrYouWillBeFired" in the function name. https://github.com/facebook/react/blob/80bff5397bf854750dbe7c286f61654ea58938c5/src/umd/ReactUMDEntry.js#L21 https://github.com/facebook/react/blob/80bff5397bf854750dbe7...