4 ms·
The Codemirror codebase [0] is simply written and richly commented, and using Codemirror itself in a project is a pleasure. Tellingly, Marijn Haverbeke, Codemi
by bijection 7y ago
The Codemirror codebase [0] is simply written and richly commented, and using Codemirror itself in a project is a pleasure.
Tellingly, Marijn Haverbeke, Codemirror's creator, is also the author of the excellent 'Eloquent Javascript' [1].
[0] https://github.com/codemirror/codemirror https://github.com/codemirror/codemirror
[1] http://eloquentjavascript.net/ http://eloquentjavascript.net/
- lol768 7y agoIt's unfortunate that the author doesn't appear to understand the value of a strict Content-Security-Policy.
- lol768 7y agoFor context, see this GitHub issue: https://github.com/codemirror/CodeMirror/issues/4937 https://github.com/codemirror/CodeMirror/issues/4937 Author is unwilling to change a handful lines of code to make the package compatible with a strict style-src. Why does this matter? You can exfiltrate data such as CSRF tokens using inline styles from a HTML injection vulnerability: https://medium.com/bugbountywriteup/exfiltration-via-css-injection-4e999f63097d https://medium.com/bugbountywriteup/exfiltration-via-css-inj...