[Xerte-dev] Upload and security

Julian Tenney Julian.Tenney at nottingham.ac.uk
Tue May 21 10:00:23 BST 2013


Just reprising a recent conversation about uploading javascript. You guys weren't keen. I just uploaded a txt file with javascript in it, loaded via a script tag in the bootstrap template and it - of course - executes, but we knew that anyway.

Is it the case that only authorised users - those logged in - can get anything through upload.php? Should authorised users be able to upload javascript?

Second and slightly related question, playing around with the bootstrap template wizard: I got it adding canvas, and thought about other userful building blocks for developers. You could define them in a text icon <canvas width="500" height="350"/> and then script them from a script icon, so are we gaining anything at the expense of confusing users who don't know what scripts and canvases do? I just though 'well, where does it end? Divs, styles, etc' and we can do it all with text anyway. But in looking at some of this stuff, it would really be handy to be able to upload scripts, because writing anything more than trivial in the wizard is going to be gribbly.

What do you think?

[cid:image001.png at 01CE560A.0271B0B0]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nottingham.ac.uk/pipermail/xerte-dev/attachments/20130521/f2bfcd31/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 104998 bytes
Desc: image001.png
URL: <http://lists.nottingham.ac.uk/pipermail/xerte-dev/attachments/20130521/f2bfcd31/attachment-0001.png>


More information about the Xerte-dev mailing list