ZcashFoundation / zcash-grant-system

The Zcash Foundation Grant System
https://grants.zfnd.org
MIT License
11 stars 8 forks source link

Don't render external images referenced by user-submitted content #451

Open tromer opened 5 years ago

tromer commented 5 years ago

The system currently allows <img a="..."> rendering of images stored in external websites. For example, https://grants.zfnd.org/proposals/575713843-zcash-sapling-offline-paperwallet-generatator automatically renders the image at https://raw.githubusercontent.com/ZcashFoundation/zecwallet/master/res/images/sapling%20paper.png.

This is bad website hygiene, for several reasons:

This may also apply to other user-generated content, such as discussion comments.

dternyak commented 5 years ago

Hey @tromer,

Thanks for bringing this up! We'll discuss internally as to next steps. ZF Grants has extensive moderation tools in place to assist with taking down offensive UGC should images be changed after approval, but you bring up some great points nonetheless.

Greatly appreciate your time and input on this and the other issues you've opened 😁