3 ms·
Having all three of: 1) a hypertext document viewing & retrieval system, 2) a shopping and payment system, and 3) a free-form application platform, all mixed to
by karatestomp 6y ago
Having all three of: 1) a hypertext document viewing & retrieval system, 2) a shopping and payment system, and 3) a free-form application platform, all mixed together, is simply nuts. Clicking a link in your hypertext document viewer shouldn't load another thing that kinda looks like a hypertext document but is in fact an application, maybe containing malware, without any notification that you're about to start running arbitrary code. We have those "allow download?" prompts and don't auto-run downloaded executables for a reason. JS in the browser has way too much power to be secure. Just letting it ever initiate a remote connection without explicit user say-so, or to modify form contents being sent, any of that stuff, is probably enough to disqualify it as a sensible thing to include in your hypertext browser.
I actually think #2 could probably co-exist with #1 pretty well, and more securely than it could with #3. Would mean building a payment flow and (maybe) a shopping cart directly into the browser. Challenging, but way less work than the 50,000,000 (and counting) implementations of those in HTML+CSS+JS have been been.