I don't think that's it. It wasn't a security issue and p intentionally added in some HTML to make it not work specifically on Soapbox. You could probably find a similar trick for Mastodon or Misskey (there was that issue with image rendering in Misskey that broke the whole UI, remember?)

Plus the PR whats-his-name submitted didn't even have test/specs in them. You can just patch every dump thing p does unless it's an actual security issue ....

Also wasn't there a Pleroma security issue? Why isn't anyone talking about that?

Reply to this note

Please Login to reply.

Discussion

nostr:npub109x0x9dlft64y4h9vz9mxu92qpqn752sd8p4xe2zkcanlzmk2fcq3pwvvl

>Also wasn't there a Pleroma security issue? Why isn't anyone talking about that?

because it was fixed as soon as it was discovered

nostr:npub109x0x9dlft64y4h9vz9mxu92qpqn752sd8p4xe2zkcanlzmk2fcq3pwvvl

>You could probably find a similar trick for Mastodon or Misskey

there was a trick for mastodon, you could post a giant text (the entire bible) and the script hiding the text broke, so the text was displayed in full. Gargron didn't bitch about bad actors and quietly fixed the issue.