4 ms·
Ok. So you're editing a sheet on google docs, you highlight part of it to copy into another doc. You hit ctrl+c. What happens? Do we not let Google modify wha
by ArchReaper 7y ago
Ok. So you're editing a sheet on google docs, you highlight part of it to copy into another doc. You hit ctrl+c.
What happens?
Do we not let Google modify what you just copied to inject the actual rich-text version of what you highlighted, as opposed to the presentation-formatted version you're seeing as a user in the editor UI?
What can actually be done if we allow the 'good actors' to continue working as needed?
- pavel_lishin 7y agoLet's handle this like we handle things like location tracking, notifications, etc: ask the user. Except I don't think we should ask the user, because everyone will blindly click yes. I think we should disable this by default, and let Google Docs, etc., remind the user via some in-app modal with step-by-step instructions. If someone actually needs this functionality, let them do the work to unlock it for a given website. 99.99999% of the web has no good reason to be modifying a user's clipboard.
- ArchReaper 7y agoI encourage you to read through the OP first on why your suggestion (remove copy-modification entirely) is not reasonable.
- pavel_lishin 7y agoAh: > The metro.co.uk code inserts an off-screen-positioned element with the disclaimer into the selection range, and you could just listen for selectionchange and/or mouse drag and/or keypress events to detect selection changes, and add/remove such an element based on those events. Well, shit.
- roywiggins 7y agoMy favorite scummy thing done to mess with browsers is to insert a noscript meta refresh redirect just to catch anyone who refuses to run the JavaScript adware embedded in their crappy local news website CMS. It must be standard in some local newspaper CMS and I've only ever seen it used on that sort of site. Never underestimate newspaper publishers' CMS vendors' ingenuity.
- weaksauce 7y ago> Do we not let Google modify what you just copied to inject the actual rich-text version of what you highlighted, as opposed to the presentation-formatted version you're seeing as a user in the editor UI? could you not have a two tiered clipboard that is exposed via javascript for the webpage interactions(to solve the copy and paste issue with rich text inside google docs) but have the main paste system be synced with the system clipboard and that restricts the copy and paste to visible text/non-javascript hijackable(stops the manipulation of the clipboard to inject malicious code for terminals or even the annoying injection of "this snippet was copied from example.com/xyz") I haven't thought too hard about the downsides to this or how hard it would be to implement but i'd be curious to see any discussion on some kind of approach like this.
- rhn_mk1 7y agoIdon't know what the "correct" solution for that could be. I can come up with some half-baked ideas, like whitelisting, web-app bifurcation (we have reader mode, why not app mode?), or allowing for some amount of modification if clipboard events are enabled. What's clear to me is that the situation we have now is suboptimal, that coming up with a better solution will take up some time, and that incrementally fixing the current situaton completely will take enough time to find a better solution in the meantime.
- deleted 7y ago[deleted]