[Xerte-dev] Re: Upload JS
xerte at pgogywebstuff.com
xerte at pgogywebstuff.com
Fri May 10 13:28:52 BST 2013
The option makes sense, but I think it's a big risk
Pgogy Webstuff http://www.pgogywebstuff.comMakers of Web things of a
fair to middling quality
----- Original Message -----
From: "For Xerte technical developers"
To:"For Xerte technical developers"
Cc:
Sent:Fri, 10 May 2013 09:57:15 +0100
Subject:[Xerte-dev] Re: Upload JS
We could just add as an optional setting in management to allow JS or
anything else that would be insecure, off by default and allow the end
user to choose… on a very closed system I agree it would be good.
Regards,
John Smith
Learning Technologist
School of Health & Life Sciences
Glasgow Caledonian University
FROM: xerte-dev-bounces at lists.nottingham.ac.uk
[mailto:xerte-dev-bounces at lists.nottingham.ac.uk] ON BEHALF OF Julian
Tenney
SENT: Friday, May 10, 2013 9:49 AM
TO: For Xerte technical developers
SUBJECT: [Xerte-dev] Re: Upload JS
Fair enough then.
Shame.
FROM: xerte-dev-bounces at lists.nottingham.ac.uk [1]
[mailto:xerte-dev-bounces at lists.nottingham.ac.uk [2]] ON BEHALF OF Pat
@ Pgogy
SENT: 10 May 2013 09:00
TO: For Xerte technical developers
SUBJECT: [Xerte-dev] Re: Upload JS
Yes
On 10 May 2013, at 07:59, Julian Tenney wrote:
Thinking aloud here, you can write javascript in the bootstrap
template – so it would probably be handy if you could upload a .js
file, because anything more than trivial is going to be a right pita
to write in the wizard. .js is currently blacklisted. Given all the
other security updates recently, do you think we are opening up a
major hole if we allowed .js? Either by uploading a script file, or by
pointing to a url somewhere?
_______________________________________________
Xerte-dev mailing list
Xerte-dev at lists.nottingham.ac.uk [4]
http://lists.nottingham.ac.uk/mailman/listinfo/xerte-dev [5]
Glasgow Caledonian University is a registered Scottish charity, number
SC021474
Winner: Times Higher Education’s Widening Participation Initiative
of the Year 2009 and Herald Society’s Education Initiative of the
Year 2009.
http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html
Winner: Times Higher Education’s Outstanding Support for Early
Career Researchers of the Year 2010, GCU as a lead with Universities
Scotland partners.
http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html
Links:
------
[1] mailto:xerte-dev-bounces at lists.nottingham.ac.uk
[2] mailto:xerte-dev-bounces at lists.nottingham.ac.uk
[3] mailto:Julian.Tenney at nottingham.ac.uk
[4] mailto:Xerte-dev at lists.nottingham.ac.uk
[5] http://lists.nottingham.ac.uk/mailman/listinfo/xerte-dev
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nottingham.ac.uk/pipermail/xerte-dev/attachments/20130510/dd838894/attachment.html>
More information about the Xerte-dev
mailing list