CSS Bug:Abuse of <sup> and <big> can escape post box
-
Repeated application of <sup> and <big> can be used to cause content to appear outside of the post box
Example: This is in wrong place.
Example: <sup><big><sup><big><sup><big><sup><big><sup><big><sup><big><sup><big><sup><big><sup><big><sup><big><sup><big>This is in wrong place.
-
Discourse default only. However @PJH deals with the tags seems to nullify it
-
right.... BRB. ;-)
-
Off to meta?
-
Comparing...
This is in wrong place.
xxx
Edit..
Ah - nested too deeply - that's why - it's hidden.
1
2
3
4
5
-
-
try.d for comparison:
-
Here on
Discourse Default
:
-
Here on
TDWTF Default
-
Discourse default only. However @PJH deals with the tags seems to nullify it
I'm fairly confidant that it's this that's neutering it:
/** Stop nested kbd's hanging FF - duplicate on mobile to keep appearance the same https://meta.discourse.org/t/dos-deeply-nested-kbds-hangs-firefox/17991/4 */ kbd * * { display: inline-block; } div.cooked * * * * * * * * * * * * * * * * * * * * { display:none; } #reply-control .wmd-controls #wmd-preview * * * * * * * * * * * * * * * * * * * * { display:none; }
-
I would agree with that
-
hrmmm......
I don't know that we entirely care about this.. abuse can be classified as "don't use standard formatting to do annoying things".
Under penalty of suspension, etc.
Not for this report, I mean if people were doing this just to be annoying all the time.
not that i disagree with the sentiment..... but.... well.
-
If only they did something like whitelisting tags. If only they had an editor that didn't require 3 different markup languages. If only …
-
Community Server whitelisted all tags and then Alex had to use the censoring function to block script tags.
-
yes, that bug doesn't work here because I toasted everyone's Firefox cat video browsing experience with it by accident during the early spoilerplating fun, so PJH fixed it with CSS... I think meta.d might have fixed it too at one point but rolled the change off because some supernesting of tags is legal/required in dicsourse to accomplish any type of half-decent formatting. All of which means, you can break every FF browser out there*.
[spoiler]Speaking of which.. this is merely annoying and doesn't crash the entire browser. [/spoiler]*as of whatever FF version it was 538 versions ago that couldn't handle super-nested <KBD> tags.
-
oh, i guess pjh turned that CSS back off too. at least, that last kbd nest worked for me. i pity the FF users .
-
@codinghorror said:
...but I've got this nice mod-hammer and I'd like more excuses to use it... do we have to fix it???
Filed under: paraphrasing
-
-
I wonder if you can...
Damn. Won't render the emoji.
-
Will it break the bounds of a post?
Hello, world!
Edit
The answer is no.
Filed under: we still can't agree with whatever Morbs just said :-(
-
-
aka Fakemoji™ tags
-
-
There's a fix for @accalia's "horizontal rule in user card" bug, too. Solution: do not allow horizontal rule in user card. Apparently still allowed in profile.
-
yeah that was a y fix.
-
There's a fix for
@accalia's "horizontal rule in user card"every Discourse bug, too. Solution: do not allowhorizontal rule in user card. Apparently still allowed in profile.users to post any contentThere, shortened the development cycle a few years.