The web's clipboard, and how it stores data of different types
alexharri.com
alexharri.com
Our society sets limits based on the most selfish. Our computers get limitations based on the most effective threat.
Depreciated means gone down in value.
Deprecated means made obsolete.
I hear this all the time at work. Drives me nuts.
Irregardless, I could care less.
I also adore "very unique"
Which means "literally" is now its own antonym. Pretty wild
What is "learnings"?
In 2016 Grammarist was to the point.
"Learnings is a pluralization of an erroneous form of learning as a singular noun. Said singular noun (e.g., a learning) does not exist, at least according to most dictionaries. Colloquially, especially in the medical field, learnings means specific items that were newly discovered or learned."
https://www.quora.com/What-is-the-plural-form-of-learning-Is...they're since softened that stance and now discuss how it is poorly used.
Another game I find the machine plays on me, is uplifting what I think is ASCII into UTF-8 or iso-latin1 which latterly invokes the clippy-like "I changed those quotes to be more aesthetic thank me later" behaviour which of course, I did NOT want. If I wanted `this' I would not have typed 'this'
Needless to say, some people weren’t happy about it. But it was a nice project to create awareness that it was possible to read the clipboard at any time.
https://support.apple.com/en-gb/guide/security/secf78dbe639/...
- 0. https://apps.apple.com/us/app/pasteboard-viewer/id1499215709
- 1. https://apps.apple.com/us/app/actions/id1586435171I didn't even know about isTrusted until a couple of weeks ago when I was writing some widgets to speed up some tasks by automating a bunch of web controls. I couldn't get my auto-paste to work, discovered that flag and went down a rabbit hole of trying to over-ride a safety mechanism on my own local browser (not easy!).
Somehow my Bank webapp was able to 2FA prompt me on sign-in with my hostname (aluminium). How did it get that? And when using their site from mobile it's able to see the text with the 2FA code and auto paste it in! Wow/How? Pixel+Chrome or Linux+Chrome.
One of these days I'm gonna log in with the debugger active.
I'm not sure why they would go to the trouble of getting the web app to talk to the phone app directly, but it is possible.
I don't have any banking app installed on either device.
It's confounding.
This is not the exciting early days of the interwebz where script kiddies run amok and it’s mostly for the geeks anymore, it’s where government-affiliated gangs are launching ransomware attacks on critical infrastructure in order to finance nuclear programs. Accessing arbitrary resources on your local machine is how that happens.
Web apps, given a modern browser, naturally have stricter sandboxing, but native apps are treated as untrusted on any modern OS, too. If I launch anything new, the dialog will have me confirm before it accesses anything other than its isolated app data directory.
It is somewhat crazy that macOS doesn’t do that yet.
But the comment I replied to was talking in general terms. Yes, for some APIs native apps are for now more trusted than Web apps, depending on the OS, but the trend is that they are becoming less and less trusted.
A really nice deep enough dive into some of that nuance.
I know that’s a lot more words to say a similar thing, but it avoids two problems with how you put it:
1. Not everyone will share your preference. (I’d hazard a guess that it’s a minority preference, albeit one I mostly share.)
2. It’s self-contradictory. The “damn text I copied” is not just an array of characters: it often includes formatting; it frequently interpolates other content that isn’t even text at all.
The latter is largely the basis for the former. You—and I, mostly!—might be after that array of characters. But many many people are after that richer content, and would be utterly baffled by copying something rich only to get that array of characters on the other side. And quite a lot of people would have little recourse to get what they want.
This is why the multipart clipboard solution is a pretty good compromise. It could be better! It could definitely accommodate the preference for plain text. But it can only be better for those of us with that preference, without regressing for the much more common preference, by keeping the common preference as default.
In many cases I do not particularly care whether an email is in 12pt blue Verdana or 11pt black Arial, I absolutely care about there suddenly being a big blue word in the middle of my otherwise-consistent paragraph.
So neither "rich text" nor "plain text" are really correct: often plain text is good enough, but sometimes it's easier to correct the rich text.
More generally, when editing a document I want to be able to view both formatted text and "escaped" contents (like "view source"), and when copy-pasting or saving text, I want to be able to convert formatted text into "escaped" text to diff, and also paste text without misinterpreting asterisks and angle brackets as formatting information (until I explicitly copy text as source and paste as formatted).
I use Obsidian for note taking, and discovered one very useful feature: if you paste formatted text, it removes everything except what can be handled in markdown (approximately, things corresponding to html tags, not to styles/CSS). You can then copy it back out as html and paste it and it will have exactly the right amount of formatting.