11 ms·
A collaborative spreadsheet in less than 45 lines of JS, one library used
- justinwi 13y agoSweet. How do you do I make it so not every Joe can hack the sheet?
- deleted 13y ago[deleted]
- joshribakoff 13y agoYou'd have to parse the cells as some sort of DSL that only allows mathematical tokens, as opposed to eval which allows access to the full arsenal of the JS language. But I think excel is Turing complete
- wwweston 13y agoBrings up the interesting question -- I wonder what turing-complete DSLs have drop-in JS libraries you could use to replace the call to "eval" here.
- icebraining 13y agohttp://nayuki.eigenstate.org/res/brainfuck-interpreter-javascript.js http://nayuki.eigenstate.org/res/brainfuck-interpreter-javas...
- vj44 13y agoDope.
- gmjoe 13y agoOh boy. I can't wait to see what someone else can do with 60 lines of JS, and two libraries used!! [Note: not being sarcastic. Think this is a genuinely awesome way to respond to first post!]
- leokun 13y agoCollaborative eval with the world, I'm glad I wasn't logged into jsfiddle when I opened that.
- FiloSottile 13y agoSince jsFiddles run user-generated code by design, I hope that they correctly sandbox and use HTTP-only cookies anyway.
- Breefield 13y agoCareful, this code runs eval() on all spreadsheet fields. Someone can "collaboratively" steal your jsfiddle.net cookies.
- srobertson 13y agovery cool, probably need a few 100 more lines of code to stop XSS but awesome none the less.
- mayop100 13y agoIt would be nice if people could lay off the script injections. It's clearly insecure, but that's not really the point. It makes the experience worse for everyone if you alert(), etc.
- X4 13y agoyup. I guess some couldn't resist the urge. I hope there aren't more malicious minds, trying to steal cookies or stuff.
- stuross 13y agoAlmost certainly someone is stealing cookies and this should be taken down soon. However, I actually enjoyed this post and was really informative all around.
- FiloSottile 13y agoFiddles run unsecure code by design, so they do in a separate domain.
- X4 13y agosource: http://hastebin.com/verowotihe.html http://hastebin.com/verowotihe.html
- jcampbell1 13y ago> It's clearly insecure, but that's not really the point. No, that is the point. I even pointed it out hours ago: https://news.ycombinator.com/item?id=6727448 https://news.ycombinator.com/item?id=6727448 The failure is the lesson. The previous version was a clever hack written by a clever person. This is ignorance, and the lesson is that allowing users to run arbitrary code on other user's computers is bad idea.
- FiloSottile 13y agoI'm pretty sure that OP knew the issue, not just you, so it's not ignorance. And it's not the moment to cite The Good Parts either. There is no failure here to be seen. There is a clever hack to make a spreadsheet shared quick and dirty. Just a reminder that all the JS code you run, in particular on jsFiddle, is untrusted and is part of the security model of the JS engine in your browser that evil JS code must not be able to do any harm. If it did, report it to the browser vendor and earn a bounty.
- RokStdy 13y agoI like the craziness that this devolved into. It's funny when a bunch of people are all editing like mad. I had the thought that it'd be fun to have a contest using jsfiddle to start from some point, like the excel (lite) clone in 30 lines, and add the best/coolest feature in some limit of lines. It's really wonderful how ingenuity stacks.
- krapp 13y agoSuch hax. I wonder if a collaborative drawing app could be made with this, using canvas.. I keep trying to figure out exactly how it works but then sparkleponies and alerts everywhere...
- ianbicking 13y agoNot Firebase, but you might enjoy: https://hacks.mozilla.org/2013/10/introducing-togetherjs/ https://hacks.mozilla.org/2013/10/introducing-togetherjs/
- jmacd 13y agohttps://github.com/adamwdennis/Go-Drawingboard https://github.com/adamwdennis/Go-Drawingboard
- maemilius 13y agoAnd someone killed it... EDIT: Nevermind, it's back.
- Goddel2 13y agoWow this link took about 30 seconds to turn into porn. Be warned.
- projectramo 13y agoI am waiting for someone to reproduce healthcare.gov with 100 lines of code...
- camus2 13y agothat's the spirit ! seriously it would be an awesome idea to create a website with challenges like that. create a substractive synthesizer in js in less than 1k, like old demos
- sbirch 13y agohttp://js1k.com/ http://js1k.com/
- ics 13y ago<h1>Alabama</h1> <p>Please call 205-XXX-XXXX for more information.</p> <h1>Alaska</h1> <p>Please call 907-XXX-XXXX for more information.</p> <h1>Arizona</h1> <p>Please call 480-XXX-XXXX for more information.</p> <h1>Arkansas</h1> <p>Please call 479-XXX-XXXX for more information.</p> ... Who needs doctypes, titles, or bodies...
- mariocesar 13y agoI like that everyone is collaborating to keep N S A in the last columns, that is team work !
- 10098 13y agoI think we broke it, the fiddle no longer works for me
- kav-ya 13y agoTry clearing your local storage: http://stackoverflow.com/questions/7667958/clear-localstorage http://stackoverflow.com/questions/7667958/clear-localstorag...
- Demiurge 13y agolol, I think I just got hacked from that
- ehPReth 13y agoIf the spreadsheet doesn't load you can watch the chaos unfold in real time by visiting the datastore's page directly: https://spreadsheet.firebaseio-demo.com/sy85U https://spreadsheet.firebaseio-demo.com/sy85U
- Eduard 13y agodid someone just execute remote javascript`?
- mothertrouble 13y agoWARNING: Could there be some kind of script attack ? My Safari browser freezes with 'foo' alert message from this site and it has placed itself as default website so whenever I reopen safari it freezes again. Let me know if you know how to fix this.
- elisee 13y agoI guess you could start Safari while offline to prevent the page from loading and change back your default page to something sane?
- EGreg 13y agoHow can JS make some page your default? Strange
- phaemon 13y agoIt's probably just restoring your previous session. Hold down Shift when starting Safari to avoid loading the old session data.
- mmastrac 13y agoI think I crashed it (ie: Chrome hard lockup on the tab) with this: =location.href='google.com'
- jcampbell1 13y agoThat will just throw a frame error because of the X-Frame-Options header, which is caught quickly. Browsers tend to have more problem with =while(1){}
- FiloSottile 13y agoI would love to read about who/how is blocking XSS and censoring!
- mintplant 13y agoOh, that's me: http://jsfiddle.net/sy85U/31/ http://jsfiddle.net/sy85U/31/ Just a very quick, crude little hack.
- FiloSottile 13y agoYou know what would be cool? Injecting this modified version to all clients, so that everybody act as a censor.
- granjef3 13y agoadded an array for blocked words; http://jsfiddle.net/sy85U/47/ http://jsfiddle.net/sy85U/47/
- yread 13y agoyeah blocking . (a dot, decimal numbers should be allowed) is a bit too restrictive although it works really well.
- njsubedi 13y agoI'm trying to remove the location.href thing outta there! Annoying!
- newbrict 13y agosomeone just broke everything hahaha
- rjuyal 13y agoNow I really love the feature of Chrome, "Prevent this window from creating new dialog box" ( or something like that ). Some *$%#@ put alert in the cell.
- wikwocket 13y agoNice. I look forward to the full office suite in 60 lines of JS, the email client/server in 75 lines of JS, and of course the bitcoin exchange web app in 90 lines of JS.
- asiekierka 13y agoDid you forget an operating system in 150 lines of JS? (Four libraries used)
- thatthatis 13y agoNot sure how many lines of js it uses, but here you go: http://bellard.org/jslinux/ http://bellard.org/jslinux/ http://bellard.org/jslinux/tech.html http://bellard.org/jslinux/tech.html
- gummydude 13y agothat would be a very2 long lines
- yurikoval 13y agoI think you can pull off Bitcoin in 89 lines.
- epsylon 13y agoI can build a JS interpreter in 1 line of JS.
- fareesh 13y agoI think the title should warn users of the various remote injection vulnerabilities present in the script. It took about 5 seconds for the page to change to xhamster
- imdsm 13y agoWhich would have been extremely embarrassing for someone at work. Luckily, that didn't happen to me.
- cm-t 13y agoOoups, someone has having success with XSS :/
- rnl 13y agohttp://images.retecool.com/uploads/reet-And_its_gone_original.jpg http://images.retecool.com/uploads/reet-And_its_gone_origina...
- hkon 13y agowow it's alive
- EGreg 13y agoWhy not just use TogetherJS securely?
- iancarroll 13y agoSomebody has created a bot to put script lyrics in the spreadsheet ._.
- golergka 13y agoIs it a bot or injection that maintains itself?