Yes, you can: https://stackoverflow.com/questions/5378559/including-javasc...
brb as I write a follow up article.
Yes, you can: https://stackoverflow.com/questions/5378559/including-javasc...
brb as I write a follow up article.
Yes they use Camo, but that's a proxy to ensure that you don't serve JS from the same domain as github.com so that 3rd party assets have the JavaScript domain security policy applied.
I do not believe that Camo is a sanitising proxy... just a proxy.
Seriously, can we stop inventing formats that execute arbitrary code under the hood?
[a]: Embedding the SVG directly into the HTML and manipulating it using the JavaScript in the HTML is an option, but not many people do that
[b]: We can argue all we want about whether we should be making interactive images in the first place, but the fact of the matter is, either you add it to your format, or someone else will
Edit: I think I narrowed down where you were wrong! Github "raw" endpoints for repository files DOES have a sanitizing option. But that's not Camo (camo is for remote, non repo, assets (linked in comments or in markdown)).
But as a consequence now we (still) have no easily portable vector format :'(
SVGs aren't image data. They're a set of instructions for recreating image data using a structured language. XML is very good for data like that.
However I agree with saagarjha that it is very easy to write code to emit SVG, which is nice.
But I think he's right - it would be nice if there was a "proper" binary vector format that was widely supported.
print(f"""<rect x="{x}" y="{y}" width="{w}" height="{h}"/>""")
I find this eminently easier than working with a binary format.Think about how you write Protobuf files for example.
If you open the SVG file directly, then JavaScript will be executed. But any hosting platforms that hosts your content on their domain should filter out any JavaScript on SVG as it would on HTML.
That's definitely not a thing that happens. Web servers just serve the file as-is.
FYI millions of readmes have had SVG badges for years.
For example, you could post one of those SVGs in every issue thread of a GitHub project if you wanted to mess with someone.
Not eligible for a bug bounty though since this issue has been known (but not fixed) for years.
For example, what happens when you right-click "View image" on an svg file? Does embedded JS get run in that case?
Servers can use CSP http headers to disable javascript execution completely AFAIK. Obviously older browsers like IE that do not support CSP will be vulnerable, but at that point, IE should be simply banned by Webservers, for the sake of the user.
They basically wanted everything that Flash had.
Would be interesting to try to find a hole in this.