/dev/posts/

Risk of reflected cross site scripting and Content-Security-Policy bypass in the WebSub intent verification

Published:

I was reading the WebSub specification (formerly PubSubHubbub) when I found that there was a risk of reflected browser-side code injection (reflected cross site scripting, reflected XSS) in the WebSub intent verification exchange.

Read more…

WebSub sequence diagram

Published:

A sequence diagram for WebSub (formerly PubSubHubbub).

Read more…

Page 1 of 1 | | | JSON Feed | Atom Feed | RSS Feed