https://bugzilla.wikimedia.org/show_bug.cgi?id=70672

--- Comment #27 from Chris Steipp <[email protected]> ---
I talked with Kunal about this yesterday. My perspective is that admin
controlled css is probably the least likely place someone is going to inject
something malicious. The user controlled css is the part that scares me the
most.

I'd be ok with a config option to allow Common.css and the skin css files
through. I'm not sure how much work that would be in resource loader.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to