3 ms·
> can you do something alternative which allows you to have a like button, but without including third party script? How about create a JavaScript library that
by buddydvd 15y ago
> can you do something alternative which allows you to have a like button, but without including third party script?
How about create a JavaScript library that sandboxes execution of third-party scripts by loading them in iframes based off of a different domain? This would allow site owners to embed Google Analytics or FB Like buttons without worrying about the third-party scripts getting compromised or becoming malicious.
- deleted 15y ago[deleted]
- teh 15y agoMost social plugins already have an iframe option. E.g. search for iframe in http://developers.facebook.com/docs/opengraph/ http://developers.facebook.com/docs/opengraph/ Edit: I think I may have misunderstood you. Did you mean embed an iframe and using postMessage to control it?
- buddydvd 15y agoThere's a difference between the iframe version of Facebook's like button and the XFBML version. The XFBML version, for various reasons, is preferable to the iframe version (e.g. say you want to subscribe to the edge.create event to determine if someone clicked on the like button). Now, if you want to add the XFBML version of the like button, you'd have to embed Facebook's JavaScript SDK script (https://connect.facebook.net/en_US/all.js https://connect.facebook.net/en_US/all.js) to your site. If connect.facebook.net ever gets compromised via a fake SSL certificate, your site will also be compromised. Instead of letting third-party scripts run on your main site, it may be safer to let them run within an iframe based off of a different domain so that a compromised third-party script doesn't compromise your main site.
- unfasten 15y ago> How about create a JavaScript library that sandboxes execution of third-party scripts [...] There has been some work done in this direction. I don't know how active the project is, but it's called ADsafe (http://www.adsafe.org/ http://www.adsafe.org/). It's a subset of regular JavaScript and doesn't allow access to global variables or the DOM, instead giving access to an ADSAFE object to limit the access of the script. ADsafe makes it safe to put guest code (such as third party scripted advertising or widgets) on a web page. ADsafe defines a subset of JavaScript that is powerful enough to allow guest code to perform valuable interactions, while at the same time preventing malicious or accidental damage or intrusion. The ADsafe subset can be verified mechanically by tools like JSLint so that no human inspection is necessary to review guest code for safety. The ADsafe subset also enforces good coding practices, increasing the likelihood that guest code will run correctly. Some of the things removed: - Global variables: Limited access to Array, Boolean, Number, String, and Math is allowed. - Dangerous methods and properties: arguments callee caller constructor eval prototype stack unwatch valueOf watch - Date and Math.random: Access to these sources of non-determinism is restricted in order to make it easier to determine how widgets behave.