5 ms·
Show HN: HN comments sidebar bookmarklet
- samstave 3y agoGreat!, would be cool if you added "transparency" slider to the overlay? Or ability to snap to split of both in same page as well as an overlay.
- Agree2468 3y agoThere was an extension called Epiverse that used to do this + reddit comments, I dearly miss it. Although I began to notice that I was more concerned with the comments than the pages themselves.
- toomuchtodo 3y agohttps://epiverse.co/ https://epiverse.co/ Relevant comment: https://news.ycombinator.com/item?id=30187483 https://news.ycombinator.com/item?id=30187483
- puika 3y agoVery handy. Ironic that it cannot work with this very post due to github's CSP
- tough 3y agoVery cool, would be nice to be able to somehow open all links from hn directly with the side-loaded comments!
- srimukh 3y agoThanks! That’s even better — although I think you’d need to create an extension out of this to be able to do that.
- arkadiyt 3y agoThis is trivially vulnerable to XSS [1]. Someone can leave a comment of the form: https://"><script>alert(1)</script> and if you click the bookmarklet for the page that comment was discussing then their javascript will execute in your logged in context on that website. [1]: https://gist.github.com/postmalloc/e2602752d46c5b9dee24462356f96cca/0bad0427e7c1f1362e3933ef9dc6c56194513f35#file-hn_sidebar-js-L24 https://gist.github.com/postmalloc/e2602752d46c5b9dee2446235...
- srimukh 3y agoThank you for spotting this! I updated the code to escape some special characters. For people reading this, the parent comment is referring to this line[1] from a previous revision of the gist. [1]: https://gist.github.com/postmalloc/e2602752d46c5b9dee24462356f96cca/828093e63f1df6b451a0466047d435893a74aa8f#file-hn_sidebar-js-L87 https://gist.github.com/postmalloc/e2602752d46c5b9dee2446235...
- arkadiyt 3y ago> For people reading this, the parent comment is referring to this line[1] from a previous revision of the gist. That was not the line, it was linking to this innerHTML call: https://gist.github.com/postmalloc/e2602752d46c5b9dee24462356f96cca/revisions#diff-b20d0ef6fa2913528dedbeb55da873d05c7b29ccf8b0fc2ebfc9cdd999c636f2L37 https://gist.github.com/postmalloc/e2602752d46c5b9dee2446235... Also as a defense mitigation I don't think escaping is ever going to be effective, it would be better to create anchor elements directly. With your current approach I can still XSS with, for instance: https://"onmouseenter=alert(1)"
- srimukh 3y agoThanks! For now, I added a warning under the gist. Not that this is an excuse, but I put this together in about 30 minutes using GPT-4 for fun without much consideration about robustness or security. I will maybe try to rewrite it when I find time.
- deleted 3y ago[deleted]
- jfdi 3y agoPlease do! Besides being a fun exercise it’s also a neat idea. Comments from the HN community make the content posted almost always more interesting imho
- 3y ago