On 02/01/2018 07:18 AM, Seb wrote:
It tells quite a bit about the complexity of Ddoc that I had to add support for -D to run.dlang.io ...
[...]
I'm not a fan of Ddoc by any means, but that has been fixed in Ddoc does this too now: https://run.dlang.io/is/75Z55o

Uhh, is it a good idea to generate documentation on run.dlang.io? Isn't this an open invitation for XSS?

Simple example, one can replace all links on the page with malicious ones:
https://run.dlang.io/is/wYLpVx

Reply via email to