Forum OpenACS Development: Re: Re: Security parameters in kernel

Collapse
Posted by Malte Sussdorff on
The moment we allow image tags I'd immediately revoke Site Wide Admin from all people. Though they are a nice feature Ben, they open up a place for attacks that has been discussed quite a lot and especially with a site where anyone can post, this is a critical security issue. Take into account that I can put any URL in an image tag, including the one that gives a certain user_id SWA access.