This look like a really great module that I would like to use, but wanted to know if the security issues listed on the project page have been resolved. If not, what can we do to help resolve them? I'm no security guru, but would be willing to pitch in what I can in time or $$. Thanks.

Comments

greggles’s picture

I think it would be good to clarify specifically what the security issue is so others can help solve it.

kirkcaraway’s picture

On the main project page for this module, it lists this:

This module needs a security review because of its reliance on cross site scripting. If you have skills in JavaScript security and are interested in this module, the maintainer would appreciate your feedback. Do not use this module on a production site until the security implications are understood and documented.

I don't see any follow up for this concern, which seemed so important that the developer put this warning on the project page.

Thanks.

Anonymous’s picture

There are no known security issues, but I also nobody has reviewed it. The site relies on cross site scripting, which would allow the Drupal site to have some control over the page where it's invoked. This problem needs to be documented as a risk that are common to tools like this and some browsers (Firefox) have default security settings that make this bookmarklet unusable.

japanitrat’s picture

can you explain which setting that is?