We Give a F*** How the Site Loads
dt.deviantart.com
dt.deviantart.com
Originally the call was named 'getSearchResults'. Over time, we made some non-backwards-compatible changes to the search call, and following our usual naming standards, named the new call 'getSearchResultsEx'.
Additionally, for ease of debugging, when we hit the API endpoint, we add the method name as a GET param. Makes it much easier when scrolling through Firebug's network tab to find the API request you need to examine, since they all hit the same php script.
It turns out that in some countries, you can't visit a url that contains the word 'sex'...and the filter is case insensitive.
If your public library censors profane words, you should fucking riot.
Wait what? What filters are checking CSS files, and why?
(edit: why does double * get escaped away on here.)
* text * italicizes, like so: text.
(Putting spaces around the * avoids this behaviour).
Unsurprisingly these types of filters don't have a lot of understanding of what is going to be displayed to the user vs not, but then again they probably don't need to to satisfy their target audience quite well.
In deviantART's case, the F-word was inside a CSS comment, thus supposedly never displayed to the user. So it's weird to block a file for that case.
The irony here is that we didn't have to do anything to fix this bug (well, we did have to rename an image file that had a vulgar name!).
I don't think that it's the actual CSS, but rather the linked content which triggered the filters.<span class="fword"></span>
.fword:before { content: "fu"; }
.fword:after { content: "ck"; }
<span class="fword"></span>And home based filters do the same, or work at the browser level.
So https doesn't help at all.
I imagine DOD requirements are the same.
The internet was fast enough, but we quickly discovered that we couldn't access google analytics (google.com/ANALytics) without a VPN or socks proxy back in the USA.
I suspect text-based web content filters tend to have fairly high false-positive rates in general.
You don't want this happening to you: http://www.snopes.com/business/consumer/bastard.asp
Although I still find myself typing console.log("WHY THE FFFUUU") on annoying JS bugs...
While it's excruciating and boring to use plain test data, you'll be glad you did it when you have an accidental leak between environments.
I mean, there's no reason to expose ugly stuff like that... developers WILL swear in comments, so just make sure it doesn't get out the front door...
The file in question was blocked by their stupid proxy because its name was "brandSansExtended", which happens to contain the substring "sex".