
<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.jmol.org/index.php?action=history&amp;feed=atom&amp;title=User_talk%3AIlmari_Karonen%2FJS_injection_demo</id>
	<title>User talk:Ilmari Karonen/JS injection demo - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.jmol.org/index.php?action=history&amp;feed=atom&amp;title=User_talk%3AIlmari_Karonen%2FJS_injection_demo"/>
	<link rel="alternate" type="text/html" href="https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;action=history"/>
	<updated>2026-06-13T07:48:56Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.32.0</generator>
	<entry>
		<id>https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5529&amp;oldid=prev</id>
		<title>Ilmari Karonen: seems to be fixed now</title>
		<link rel="alternate" type="text/html" href="https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5529&amp;oldid=prev"/>
		<updated>2008-12-08T21:50:09Z</updated>

		<summary type="html">&lt;p&gt;seems to be fixed now&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 21:50, 8 December 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l8&quot; &gt;Line 8:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;:: Ilmari, can you please check the page again? I have done some fixes in the extension and it is now updated in this wiki. No javascript should be executed by the extension now. --[[User:AngelHerraez|AngelHerraez]] 21:50, 8 December 2008 (CET)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;:: Ilmari, can you please check the page again? I have done some fixes in the extension and it is now updated in this wiki. No javascript should be executed by the extension now. --[[User:AngelHerraez|AngelHerraez]] 21:50, 8 December 2008 (CET)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;::: Yup, seems to be fixed now.  Thanks.  --[[User:Ilmari Karonen|Ilmari Karonen]] 22:50, 8 December 2008 (CET)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ilmari Karonen</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5528&amp;oldid=prev</id>
		<title>AngelHerraez at 20:50, 8 December 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5528&amp;oldid=prev"/>
		<updated>2008-12-08T20:50:13Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 20:50, 8 December 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l6&quot; &gt;Line 6:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;:As a random, unprivileged editor, I'm not supposed to be able to run arbitrary JavaScript in your browser in the wiki's context.  If I can do that, I can e.g. make edits or send e-mail to other users in your name, obtain information about your computer and your browsing habits that the wiki software doesn't normally reveal, or even trick you into giving me your wiki password, which I can then try to use to log onto other sites.  The last part isn't quite as easy on the latest MediaWiki versions than it is on e.g. MediaWiki 1.12 (as used on this site), since a few of the more obvious ways to do that have been plugged, but it's certainly still possible.  --[[User:Ilmari Karonen|Ilmari Karonen]] 21:22, 29 November 2008 (CET)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;:As a random, unprivileged editor, I'm not supposed to be able to run arbitrary JavaScript in your browser in the wiki's context.  If I can do that, I can e.g. make edits or send e-mail to other users in your name, obtain information about your computer and your browsing habits that the wiki software doesn't normally reveal, or even trick you into giving me your wiki password, which I can then try to use to log onto other sites.  The last part isn't quite as easy on the latest MediaWiki versions than it is on e.g. MediaWiki 1.12 (as used on this site), since a few of the more obvious ways to do that have been plugged, but it's certainly still possible.  --[[User:Ilmari Karonen|Ilmari Karonen]] 21:22, 29 November 2008 (CET)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;:: Ilmari, can you please check the page again? I have done some fixes in the extension and it is now updated in this wiki. No javascript should be executed by the extension now. --[[User:AngelHerraez|AngelHerraez]] 21:50, 8 December 2008 (CET)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>AngelHerraez</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5473&amp;oldid=prev</id>
		<title>Ilmari Karonen: I'm not supposed to be able to run arbitrary JavaScript in your browser in the wiki's context</title>
		<link rel="alternate" type="text/html" href="https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5473&amp;oldid=prev"/>
		<updated>2008-11-29T20:22:40Z</updated>

		<summary type="html">&lt;p&gt;I&amp;#039;m not supposed to be able to run arbitrary JavaScript in your browser in the wiki&amp;#039;s context&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 20:22, 29 November 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l4&quot; &gt;Line 4:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 4:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;What is the risk in letting the extension do so? Maybe the wikis are not allowed to run javascript under normal conditions?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;What is the risk in letting the extension do so? Maybe the wikis are not allowed to run javascript under normal conditions?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;--[[User:AngelHerraez|AngelHerraez]] 20:26, 29 November 2008 (CET)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;--[[User:AngelHerraez|AngelHerraez]] 20:26, 29 November 2008 (CET)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;:As a random, unprivileged editor, I'm not supposed to be able to run arbitrary JavaScript in your browser in the wiki's context.  If I can do that, I can e.g. make edits or send e-mail to other users in your name, obtain information about your computer and your browsing habits that the wiki software doesn't normally reveal, or even trick you into giving me your wiki password, which I can then try to use to log onto other sites.  The last part isn't quite as easy on the latest MediaWiki versions than it is on e.g. MediaWiki 1.12 (as used on this site), since a few of the more obvious ways to do that have been plugged, but it's certainly still possible.  --[[User:Ilmari Karonen|Ilmari Karonen]] 21:22, 29 November 2008 (CET)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ilmari Karonen</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5472&amp;oldid=prev</id>
		<title>AngelHerraez: discuss the risk involved</title>
		<link rel="alternate" type="text/html" href="https://wiki.jmol.org/index.php?title=User_talk:Ilmari_Karonen/JS_injection_demo&amp;diff=5472&amp;oldid=prev"/>
		<updated>2008-11-29T19:26:53Z</updated>

		<summary type="html">&lt;p&gt;discuss the risk involved&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Right, Jmol can invoke javascript commands, so the MediaWiki extension channels those commands.&lt;br /&gt;
&lt;br /&gt;
But most pages do run javascript.&lt;br /&gt;
What is the risk in letting the extension do so? Maybe the wikis are not allowed to run javascript under normal conditions?&lt;br /&gt;
--[[User:AngelHerraez|AngelHerraez]] 20:26, 29 November 2008 (CET)&lt;/div&gt;</summary>
		<author><name>AngelHerraez</name></author>
		
	</entry>
</feed>