Hacker News new | ask | show | jobs
by jbox 4815 days ago
"As a general rule, it's not possible to securely allow arbitrary user-provided content on a subdomain."

This rule is also good to keep in mind when choosing a domain for non-production environments!