denise: Image: Me, facing away from camera, on top of the Castel Sant'Angelo in Rome (0)
Denise ([staff profile] denise) wrote in [site community profile] dw_maintenance 2023-06-30 03:20 pm (UTC)

Re: CSS escaping

That's a security related restriction -- it was put in place because there's a category of exploits that used to be very common on LiveJournal that can happen if you don't clean certain byte strings out of user-generated CSS classes, and the fix for it has to be a little over-cautious and just clean all Unicode. Theoretically, we could probably look into whether we can step back some of the restrictions given the advances in browser technology, but it hasn't been a priority (and is unlikely to be a priority in the future) because of the risk of re-introducing security attack vectors if we aren't extremely careful and we've prioritized other efforts instead.

EDIT: actually nevermind! our security person did do that analysis while I wasn't paying attention and this next code push should reduce the restrictions on Unicode in CSS a lot. Sorry for the bad info!

Post a comment in response:

This account has disabled anonymous posting.
(will be screened if not validated)
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org