On Fri, Jan 23, 2009 at 23:13, Jesse Proulx <[email protected]> wrote:
> On Fri, Jan 23, 2009 at 2:01 PM, Mark Smith <[email protected]> wrote:
>> The rules against JS/Flash were established before we forced per-user
>> subdomains to be on.  Once everything split out to subdomains, then
>> the security policy became antiquated and should be revisited.
>
> Now that everyone's forced on to their own subdomains

Does that mean that communities will also have individual subdomains?
(Otherwise, wouldn't a rogue community be able to get cookies from
community.dreamwidth.org and have access to other communities as
well?)

Does it also mean that leading and trailing underscores will be
disallowed in usernames?

(Hm... will usernames that start with "xn__" be allowed? Then people
could register, say, xn__lite_9oa as their username, resulting in a
subdomain of élite.dreamwidth.org.)

Cheers,
-- 
Philip Newton <[email protected]>
_______________________________________________
dw-discuss mailing list
[email protected]
http://lists.dwscoalition.org/cgi-bin/mailman/listinfo/dw-discuss

Reply via email to