• ComputerGuru 7 hours ago

    Completely appalled to learn that docs.rs lets you inject any html/css/js you want into the live site (on pages documenting your crate). I love the flexibility but shudder at the security hole the size of, oh, I don’t know, the Grand Canyon.

    It’s not a new discovery, I just didn’t know docs.rs (intentionally) wasn’t blocking this. Cf https://docs.rs/pwnies/0.0.13/pwnies/

    • wonger_ 20 hours ago

      How have other doc providers handled multilingual code highlighting at scale?

      Also, seems clever to use custom elements to reduce `<span class="highlight-whatever">` to `<a-k>`.

      • zem 20 hours ago

        this looks like a truly amazing piece of work. props to the author for doing a very thorough job.

        • dcminter 9 hours ago

          Amos is horrifyingly productive!