purnimagupta / threepress

Automatically exported from code.google.com/p/threepress
Other
0 stars 0 forks source link

<form>s inside books #115

Open GoogleCodeExporter opened 8 years ago

GoogleCodeExporter commented 8 years ago
I've seen a book come through that (accidentally) had an embedded <form>
element.

On the one hand I can see some value in this, I guess, for digital
textbooks that might allow the reader to answer a question and validate it
externally.

On the other than it's a big phishing invite.  "ENTER YOUR BOOKWORM
PASSWORD HERE."  Especially if someone took the trouble to mock up the HTML
to match the Bookworm layout.

Should we kill <form> the way we already do with <script>?  

Potentially later it could be allowable on a per-book /
signed-by-a-publisher basis.

Original issue reported on code.google.com by liza31337@gmail.com on 20 Feb 2009 at 9:07

GoogleCodeExporter commented 8 years ago
It'd be nice if the implementation didn't prevent ever handling <form>s, but I'd
strip these for the time being.

Original comment by abdela...@gmail.com on 23 Feb 2009 at 3:49

GoogleCodeExporter commented 8 years ago

Original comment by liza31337@gmail.com on 23 Feb 2009 at 7:57