Hi

Could you elaborate on security reasons ? Clicking a shape or a text to 
> open a tiddler look the same to me.
>

What if I create an svg that is hosted on evilsite called "Fancy stuff for 
TiddlyWiki". It contains a script onclick="delete all tiddlers and save()"
For sure, I would need to package the stuff, with something useful and 
minify the script ;) ...
Most users don't know, that an image actually could do harm to there TW. So 
would be a perfect trojan. 

-mario

-- 
You received this message because you are subscribed to the Google Groups 
"TiddlyWiki" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to tiddlywiki+unsubscr...@googlegroups.com.
To post to this group, send email to tiddlywiki@googlegroups.com.
Visit this group at http://groups.google.com/group/tiddlywiki.
For more options, visit https://groups.google.com/d/optout.

Reply via email to