You are reading a single comment by @Velocio and its replies. Click here to read the full conversation.
  • Problem with remote images though, I don't know that stuff.

    What if you were to add client side javascript to report the dimensions of embedded remote images back to the microcosm server ? Malicious clients could mess it up, but if the server only acted on information for which all reports are unanimous then the worst a malicious client could do is take us back to the situation we're in now.

  • I have wondered about whether it's feasible to use the embed stuff to pull an image and analyse it.

    But that is a hell of a lot of overhead for an edge case bug.

About

Avatar for Velocio @Velocio started