Hacker News new | ask | show | jobs
by superzamp 4190 days ago
Nice idea, congrats on shipping.

You might want to fix this though http://sitekite.com/hello-world-2o5f7g

3 comments

On a similar topic, I seem to have broken something by putting a javascript:alert in the embed field:

http://sitekite.com/test-V2IjEA

Haha, that's always the first thing I check for. :)

http://sitekite.com/my-kickass-website-m0uAPw

yea, I'd second the xss, since using rails one sanitize call should be enough.
And setting user cookies to HTTP only.