3 ms·
Would also need to block ctrl+s/save. Which seems pretty drastic for anything other then a dedicated testing machine.
by grayfaced 5y ago
Would also need to block ctrl+s/save. Which seems pretty drastic for anything other then a dedicated testing machine.
- tyingq 5y agoAlso pasting "javascript:whatever" in the omnibar. I'm sure there's some nice version of: javascript:alert(document.body.innerHTML);
- birdman3131 5y agoYou can't actually paste that into the omnibar in chrome. It will eat the first part.
- tyingq 5y agoYes, you have to manually type "javascript:" then paste the code. Or copy everything but the leading 'j' and hand type that after pasting. Or put it in a bookmark. Also, alert() truncates the text, but makes for a nice short demo. You could append a <pre> element to the page, or similar.
- colejohnson66 5y agoTaking advantage of a long-lost HTML tag (<plaintext>) that tells the parser to switch the tokenizer to "PLAINTEXT" state[0] with no escape: javascript:document.body.innerHTML="<plaintext>"+document.body.innerHTML From MDN[1]: > The <plaintext> HTML element renders everything following the start tag as raw text, ignoring any following HTML. There is no closing tag, since everything after it is considered raw text. You could use the <pre> tag, but that can be "escaped" from if a </pre> tag exists on the page. Escaping the angle brackets with < and > would fix it, but <plaintext> is more elegant IMO. [0]: https://html.spec.whatwg.org/#plaintext-state https://html.spec.whatwg.org/#plaintext-state [1]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/plaintext https://developer.mozilla.org/en-US/docs/Web/HTML/Element/pl...
- tyingq 5y agoYeah, that works great. Then the kids just put that in a bookmark called "view-source". Probably also easy enough to make another bookmark that puts it back to normal.