MediaWiki talk:Gadget-OWIDPopup.js
Jump to navigation
Jump to search
Improvements
I notice that this gadget protects against directory transversal and makes sure the target graph comes from owid, but the owidm extension that Ryan wrote was more restrictive. It only allowed targets from the grapher directory and it sanitized and restricted the url parameters. Should this gadget be tightened? https://mdwiki.org/wiki/User:TimMoody/sandbox pops up javascript code.
I'm not sure what mwoffliner will do with these popup pages, hopefully not include them. But we had agreed to use class owid-frame, note case, as a marker for not including a section of a page in the ZIM.