loadletter / 4chan-x

Fork of 4chan X 2.x
MIT License
44 stars 8 forks source link

Security fixes. #48

Closed ccd0 closed 10 years ago

ccd0 commented 10 years ago

This should fix the stuff in #41.

ccd0 commented 10 years ago

chrome API

I derped here; you don't have a .crx version, so it's just the GM_* API. The local filenames issue (a Greasemonkey bug) is the larger concern as it can compromise anonymity. And I wouldn't be surprised if this issue of executing untrustworthy code in a trusted context causes other problems I'm not aware of yet.

loadletter commented 10 years ago

Thanks for taking your time to do this