This has a really big security flaw, if the creator wanted to be mischievous he could change his js file to do things to your logged in github account, for example set your privet repositories public.
If you want to use it you should fork it and change to bookmarklet to use your fork of the js file.
And I would always lean to the side of trust in people, I wouldn't expect you or most people here to abuse it.
Its a little bit of a pet hate, the suggested linking to JavaScript files in another persons repository. The worst was the HTML5 Shim, for a long time they suggested linking directly to their svn repo, fortunately they don't now. It was about the same time people started thinking about using the google cdn for javascript libraries and so people just did it thinking they were helping their page load times when in fact they were compromising the security of their users and themselves.
Just thinking about this, what's needed is some kind of trusted public cdn that you can send files to but cannot change so that library writers can point towards a cdn hosted version of the library without running one themselves and removing security vulnerability.
Using Google CDN places no more trust in Google than using Google Analytics or AdSense. Unless your site handled sensitive data or is mission critical, I believe it's reasonable to trust Google not to do anything malicious.
It's worth noting that the same issue exists with Chrome extensions. I wonder how strong a Google password the authors of popular Chrome extensions have.
I suspect that JS that didn't depend on the page-load to trigger it would work too. I had never considered looking at JS-enabled pages though. When I wrote my bookmarklet, I just needed to view static documentation.
Edit: I found a page with only on-click JS events, and they didn't work. Oh well...
There has ben more than a few times that I've wished to be able to do this while browsing trough random github repos, kudos to the developer, this looks very handy!
21 comments
[ 5.8 ms ] story [ 73.7 ms ] threadI mean, it has virtually nothing to do with git.
If you want to use it you should fork it and change to bookmarklet to use your fork of the js file.
Its a little bit of a pet hate, the suggested linking to JavaScript files in another persons repository. The worst was the HTML5 Shim, for a long time they suggested linking directly to their svn repo, fortunately they don't now. It was about the same time people started thinking about using the google cdn for javascript libraries and so people just did it thinking they were helping their page load times when in fact they were compromising the security of their users and themselves.
It's worth noting that the same issue exists with Chrome extensions. I wonder how strong a Google password the authors of popular Chrome extensions have.
Try your code on this page: https://raw.github.com/mrdoob/three.js/46c0a8434d3f269741a88...
And compare it with githtml on the /blob/ version of the same page: https://github.com/mrdoob/three.js/blob/master/examples/canv...
I suspect that JS that didn't depend on the page-load to trigger it would work too. I had never considered looking at JS-enabled pages though. When I wrote my bookmarklet, I just needed to view static documentation.
Edit: I found a page with only on-click JS events, and they didn't work. Oh well...
Here it is : http://news.ycombinator.com/item?id=4200790 https://github.com/jbourassa/mirrorin
There has ben more than a few times that I've wished to be able to do this while browsing trough random github repos, kudos to the developer, this looks very handy!
I've ended up using this bookmarklet on a lot of non-github.com sites too.
For instance, you can see how it renders http://c.sente.cc/hcVg/xkcd.txt here: http://i.imgur.com/DNVqd.png
here's the code in snippet form: