top | item 46261332 My Gift to the Rustdoc Team 111 points| joshka | 2 months ago |fasterthanli.me 6 comments order hn newest ComputerGuru|2 months ago Completely appalled to learn that docs.rs lets you inject any html/css/js you want into the live site (on pages documenting your crate). I love the flexibility but shudder at the security hole the size of, oh, I don’t know, the Grand Canyon.It’s not a new discovery, I just didn’t know docs.rs (intentionally) wasn’t blocking this. Cf https://docs.rs/pwnies/0.0.13/pwnies/ db48x|2 months ago Yea, it’s technically a bad idea but on the other hand there’s nothing there to steal. wonger_|2 months ago How have other doc providers handled multilingual code highlighting at scale?Also, seems clever to use custom elements to reduce `<span class="highlight-whatever">` to `<a-k>`. zem|2 months ago this looks like a truly amazing piece of work. props to the author for doing a very thorough job. dcminter|2 months ago Amos is horrifyingly productive! nicolas_gu|2 months ago The link does not work
ComputerGuru|2 months ago Completely appalled to learn that docs.rs lets you inject any html/css/js you want into the live site (on pages documenting your crate). I love the flexibility but shudder at the security hole the size of, oh, I don’t know, the Grand Canyon.It’s not a new discovery, I just didn’t know docs.rs (intentionally) wasn’t blocking this. Cf https://docs.rs/pwnies/0.0.13/pwnies/ db48x|2 months ago Yea, it’s technically a bad idea but on the other hand there’s nothing there to steal.
db48x|2 months ago Yea, it’s technically a bad idea but on the other hand there’s nothing there to steal.
wonger_|2 months ago How have other doc providers handled multilingual code highlighting at scale?Also, seems clever to use custom elements to reduce `<span class="highlight-whatever">` to `<a-k>`.
zem|2 months ago this looks like a truly amazing piece of work. props to the author for doing a very thorough job. dcminter|2 months ago Amos is horrifyingly productive!
ComputerGuru|2 months ago
It’s not a new discovery, I just didn’t know docs.rs (intentionally) wasn’t blocking this. Cf https://docs.rs/pwnies/0.0.13/pwnies/
db48x|2 months ago
wonger_|2 months ago
Also, seems clever to use custom elements to reduce `<span class="highlight-whatever">` to `<a-k>`.
zem|2 months ago
dcminter|2 months ago
nicolas_gu|2 months ago