3 ms·
Heya, creator checking in. Surprised this popped up on HN so soon after release (or at all). Although this is exactly the type of feedback I'm after. I've star
by tholman 14y ago
Heya, creator checking in. Surprised this popped up on HN so soon after release (or at all). Although this is exactly the type of feedback I'm after.
I've started looking into scanning, and stripping js/malevolence from the content ... just haven't got around to implementing anything just yet.
That said, the project is only 2 days old, if anyone is interested in contributing its all open source: https://github.com/tholman/zenpen https://github.com/tholman/zenpen
- dhaivatpandya 14y agoUnfortunately, this problem that you are trying to solve has been tried numerous times and resulted in failure. There's just too many inconsistencies in the way browsers allow loading of Javascript. Something that looks to a scanner as malevolent can actually turn up in the browser as something that ends up running. So, unless you're somehow able to sandbox everything and able to stop causing the Javascript to poke out, it is incredibly difficult to scan for JS issues such as this one, especially when you're handling user-created HTML. In fact, this is exactly the sort of problem why I created a Markdown no-nonsense editor instead (http://www.nimblenot.es/ http://www.nimblenot.es/).
- tholman 14y agoOoh, These are good insights! (nimblenotes is great too!) Perhaps it would be possible for me to save the ZenPen output as markdown (compressed) and then re-assemble it into html on load... ideally avoiding sneaky man-edited html all together.
- masukomi 14y agomy first thought was "Cool! Damn, not markdown." Security issues aside I think you'd addressed the use case for the "common man" well. I (and I think many of the geeks here) would prefer a markdown variant though. No selecting and clicking to bold things, no reaching for the mouse, etc. That being said, a the ability to bold and italicize without leaving the keyboard are pretty standard text editor features at this point that ZenPen would do well to incorporate and the functionality would be reusable in a markdown variant too.
- nosecreek 14y agoIt looks like Ctrl+b and Ctrl+i work for bolding and italicizing.
- oelmekki 14y agoOut of curiosity, why wouldn't it be enough to have a tag whitelist and filter out their attributes when reproducing the content ?
- bengillies 14y agoYou might want to checkout the HTML sanitizer from the Caja project [1]. You'll need to build it with ant first, but it's pretty good and should be able to do what you want it to. [1] http://code.google.com/p/google-caja/wiki/JsHtmlSanitizer http://code.google.com/p/google-caja/wiki/JsHtmlSanitizer