Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd also restrict the allowed CSS to the tiny portion of the spec that styles the text and maybe some basic layout. Definitely no scripting allowed.


And require that if any colours are set, both foreground and background are set. (I've seen too much breakage with assumptions about one or the other.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: