Skip to content
This repository has been archived by the owner on Jul 24, 2021. It is now read-only.

without javascript the message preview button sends the message #5434

Closed
openstreetmap-trac opened this issue Jul 23, 2021 · 2 comments
Closed

Comments

@openstreetmap-trac
Copy link

Reporter: aseerel4c26
[Submitted to the original trac issue database at 6.05pm, Wednesday, 30th November 2016]

  1. Use Firefox with Javascript disabled
  2. On https://www.openstreetmap.org/message/new/$whateverusernamehere
  3. type in a subject and message.
  4. Click "preview"

Actual: sends the message.
Expected: preview is shown or nothing happens

This could lead to unintended disclosure of private details or at least half-finished messages being sent.

Thank you!

@openstreetmap-trac
Copy link
Author

Author: TomH
[Added to the original trac issue at 9.10pm, Wednesday, 30th November 2016]

Well the whole website basically doesn't work without javascript - I mean the front page just become a big "javascript disabled" banner. So it seems highly unlikely that anybody will be visiting a page like that without javascript enabled.

Basically we assume javascript is enabled as a matter of policy and make only minimal efforts (like the aforementioned banner) to fallback.

@openstreetmap-trac
Copy link
Author

Author: aseerel4c26
[Added to the original trac issue at 7.17pm, Monday, 5th December 2016]

Okay, thanks for your comment, Tom.

Well, the described scenario was not imagined. Due to a recent browser security hole I was surfing the webpage without JavaScript - and writing messages and editing via JOSM works fine that way. :-)

Okay, if you see no easy way to just disable the preview button when JS is not active, yes, then - scrap this bug report.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant