MediaWiki talk:Gadget-OWIDPopup.js

From WikiProjectMed
Jump to navigation Jump to search

Improvements

I notice that this gadget protects against directory transversal and makes sure the target graph comes from owid, but the owidm extension that Ryan wrote was more restrictive. It only allowed targets from the grapher directory and it sanitized and restricted the url parameters. Should this gadget be tightened? https://mdwiki.org/wiki/User:TimMoody/sandbox pops up javascript code.

I'm not sure what mwoffliner will do with these popup pages, hopefully not include them. But we had agreed to use class owid-frame, note case, as a marker for not including a section of a page in the ZIM.