Recent activity
Subscribe to this feed
Mark Christian replied on January 22, 2009 21:55 to the problem "i-names no longer working for OpenID signin?" in PBwiki:
We were having some problems with people mis-understanding what the OpenID field was for, so we tightened up the validation we were using. Unfortunately, we went a bit overboard and i-names were left in the dust.
I've patched the issue and the new version should be live this afternoon. Sorry about the inconvenience.
Mark Christian replied on December 19, 2008 19:20 to the question "Is Javascript supported in PBwiki 2.0?" in PBwiki:
Just to clarify, if you have JavaScript inside of an HTML plugin, once you convert, you'll have to edit that plugin and check the "Allow JavaScript and other potentially unsafe code" checkbox.
Code that you have just pasted directly into your wiki page will still be removed when you convert to 2.0. The only way to use JavaScript in your pages in PBwiki 2.0 is in the HTML/JavaScript plugin.
Mark Christian set one of Mark Christian's replies as an official response to "Why are my num sum spreadsheets showing as File Not Found?" in PBwiki
Mark Christian replied on July 02, 2008 01:52 to the question "Why are my num sum spreadsheets showing as File Not Found?" in PBwiki:
Mark Christian replied on July 02, 2008 01:19 to the question "Why are my num sum spreadsheets showing as File Not Found?" in PBwiki:
Mark Christian set one of Mark Christian's replies as an official response to "How do I let anyone with a pbwiki account edit my 2.0 pbwiki?" in PBwiki
Mark Christian replied on July 01, 2008 21:40 to the question "How do I let anyone with a pbwiki account edit my 2.0 pbwiki?" in PBwiki:
Mark Christian set one of Mark Christian's replies as an official response to "Join the Universal Edit Button movement" in PBwiki
Mark Christian replied on June 20, 2008 17:03 to the idea "Join the Universal Edit Button movement" in PBwiki:
Mark Christian replied on May 28, 2008 17:19 to the problem "Safari is "ps"ing my file downloads!" in PBwiki:
Mark Christian set one of Mark Christian's replies as an official response to "Safari is "ps"ing my file downloads!" in PBwiki
Mark Christian replied on May 23, 2008 21:14 to the problem "Safari is "ps"ing my file downloads!" in PBwiki:
A comment on the question "Why is font always defaulting to Lucida Sans in authoring?" in PBwiki:
Segoe is the default user interface font for Windows Vista (http://en.wikipedia.org/wiki/Segoe_UI). Lucida Grande is the default user interface font for Mac OS X (http://en.wikipedia.org/wiki/Lucida_G...). – Mark Christian, on May 08, 2008 18:41
Mark Christian replied on April 23, 2008 17:29 to the question "Red and green are problems" in PBwiki:
Hi there;
I've taken a look at our notifications using Sim Daltonism (http://michelf.com/projects/sim-dalto...), a colour blindness simulator. For all but one type of monochromacy, things still seem to be quite visible.
How would you recommend we change the notifications to be clearer?
Mark Christian replied on April 17, 2008 17:21 to the question "Why does pbwiki change my links?" in PBwiki:
URLs get encoded using the standard PHP library (the urlencode function), which does it all according to common conventions. The vast majority of servers work just fine with this encoding -- in fact, this is the first instance of it not working that I've personally seen. For historical reasons, spaces get turned into pluses, which works perfectly most of the time.
That being said, there are alternative ways for us to encode URLs that might be better. I'm going to look into this and will post here if things change. In the meantime, Guy's recommendation to use TinyURL or a similar service is an excellent one.
Mark Christian replied on April 08, 2008 20:10 to the question "I'm not getting email notifications when the wiki is updated." in PBwiki:
Mark Christian set one of Mark Christian's replies as an official response to "Is Javascript supported in PBwiki 2.0?" in PBwiki
Mark Christian replied on March 26, 2008 21:48 to the question "Is Javascript supported in PBwiki 2.0?" in PBwiki:
There are all sorts of evil things you can do with JavaScript, ranging from stealing cookies to redirecting you to unsavory destinations.
The reason the HTML plugin in edit mode is filtered when the Custom HTML is not is because the Custom HTML can only be edited by an admin, someone who is presumably trustworthy. Especially on public wikis, allowing anyone to insert a chunk of random JavaScript would be incredibly dangerous.
As for the “not very Web 2.0” statement, I think you'll find that JavaScript is stripped out pretty much everywhere. JavaScript getting through the cracks means the potential for Cross-Site Scripting attacks, and those are no good.
The bottom line is that we're continually hardening PBwiki 2.0's security, including its defenses against malicious code, but it's an ongoing process. Security is pretty meaningless if the service isn't useful for people. We will re-evaluate the dynamics of unfiltered user code again as conditions change. JavaScript can do a lot of amazing things, and believe me, no one wants to see those things more than we do.
Mark Christian marked one of Ian's replies in PBwiki as useful. Ian replied to the question "Is Javascript supported in PBwiki 2.0?".
Mark Christian replied on March 21, 2008 20:54 to the problem "But my RSS feeds are enabled!" in PBwiki:
| next » « previous |
Loading Profile...
