[buddypress-trac] [BuddyPress Trac] #6772: BuddyPress Embeds for activity, user profiles, groups

buddypress-trac noreply at wordpress.org
Wed May 25 17:17:48 UTC 2016


#6772: BuddyPress Embeds for activity, user profiles, groups
------------------------------------+------------------
 Reporter:  imath                   |       Owner:
     Type:  idea                    |      Status:  new
 Priority:  normal                  |   Milestone:  2.6
Component:  API                     |     Version:
 Severity:  normal                  |  Resolution:
 Keywords:  dev-feedback has-patch  |
------------------------------------+------------------

Comment (by r-a-y):

 @imath - Your suggestions are great!

 My only concern is with enqueuing assets.

 This is what pento
 [https://core.trac.wordpress.org/ticket/32522#comment:22 mentions in the
 WP Embeds ticket]:

 > For security, we wouldn't allow JS or CSS from the remote site to be
 embedded in the page - it can too easily be used as an attack vector.

 I think this is a strong reason not to allow enqueuing assets.

--
Ticket URL: <https://buddypress.trac.wordpress.org/ticket/6772#comment:36>
BuddyPress Trac <http://buddypress.org/>
BuddyPress Trac


More information about the buddypress-trac mailing list