There is an XSS on pen.io. I posted this a while ago, but feint didn't fix it.<p><a href="http://xssdemo.pen.io" rel="nofollow">http://xssdemo.pen.io</a><p>Suggestion: It is very hard to allow HTML but remove JavaScript. Write a method called something like isJSPresent() and then after you've done your filtering, check if JavaScript is on the page. If it is, return a HTML-encoded version of the page. Then, the security of your page will rely only on the correctness of that single method, and not on the correctness of your rewriter (which is much more complex).
For better or for worse, I'm a fan of minimalism, but it has to <i>just work</i>. That's not the case currently - I'm finding this very frustrating.<p>-I made a page, then registered, but there's no way to associate a previously made page to an account. (I guess I have to change the original name to a throwaway account and start again)<p>-No way to delete a page?<p>-I tried to make a simple list of links. It works once, but when you edit the page a second time, the :link tags are no longer properly parsed.<p>-Links move around or disappear in different views. In particular, the contacts link is gone when I log in.<p>The list goes on, but... am I the only one with all of these simple usage problems? Or have people upvoted this submission without actually trying the product?
It's almost the same as something called <a href="http://jottit.com" rel="nofollow">http://jottit.com</a> from a million years ago. I think it's another exercise in futility.<p>I find the "penio" name and the phallus-like logo fascinating and intringuing, though.
You have to be kidding me: "penio"? It sounds like a foreign name for penis. Even the logo looks phallic. Come on.<p>Companies spend a fortune checking names. This site is in English and has a single letter difference.
I was looking for some demo pages, but the link at the bottom <a href="http://pen.io/showlast.php" rel="nofollow">http://pen.io/showlast.php</a> (latest pages) is actually showing only the latest, which are unfortunately frequently left empty or unmodified.<p>it would be nice to have some "pick random" link, choosing across some well visited pages.
After seeing this, I decided to attempt my own minimalist (dropbox) blog. Just need to automate the post list somehow...<p><a href="http://dl.dropbox.com/u/26639308/miniblog/index.html" rel="nofollow">http://dl.dropbox.com/u/26639308/miniblog/index.html</a><p>Not a real blog replacement, but it was fun to play with.
Wait, how is there no backend on pen.io? IT's got to be hosted somewhere, and the pages have to be stored somewhere, right?<p>Or is it simply using something like github or dropbox, and serving it publicly from there and pen.io is just a conduit?
Error pages would be nice if handled correctly,
I type <a href="http://pen.io/show" rel="nofollow">http://pen.io/show</a> ?<p>You are running apache, I believe this should be a snap :)<p>Cheers,
Jose