TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Browser Extensions and XSS

1 点作者 PlanetFunk将近 14 年前
Over the last week I've developed and released an extension for Chrome/Firefox that collapses and adds a toggle bar to each Google+ stream post.<p>I've also just released a bookmark that takes the extension code (from code.google.com) and injects it into the G+ page for those browsers that can't use the extension.<p>now, my understanding is that this is basically user-control cross-site scripting (XSS).<p>The thing is, it's exactly what all of the extensions are doing anyway, isn't it?<p>Is there something I'm missing?

暂无评论

暂无评论