Post 9m72h5DjhGmApdK4X2 by shaderphantom@awoo.space
(DIR) More posts by shaderphantom@awoo.space
(DIR) Post #9m72h4nrFU4lXNDPCC by shaderphantom@awoo.space
2019-08-21T02:42:50Z
0 likes, 0 repeats
a certain major healthcare identity provider for a certain major hospital network has managed to completely break their login page on firefox
(DIR) Post #9m72h50GVM069r1JXE by shaderphantom@awoo.space
2019-08-21T02:45:33Z
0 likes, 0 repeats
this is because their login page is an embedded okta login which requires unsafe-inline enabled in the content security policy (!!!! what the fuck!!!!!), and firefox seems to reject this by default
(DIR) Post #9m72h5DjhGmApdK4X2 by shaderphantom@awoo.space
2019-08-21T02:46:23Z
0 likes, 0 repeats
of all the industries trying to modernize for the internet still, i think the healthcare industry pulls the most nonsensically insecure and dangerous bullshit
(DIR) Post #9m72h5TKlHFjc0cWqO by shaderphantom@awoo.space
2019-08-21T02:50:57Z
0 likes, 0 repeats
it's actually just broken: the CSP the page serves includes directives that override the unsafe-inline declaration anyway. somehow chrome thinks this is normal and goes along with it, but firefox rightfully errs on the safe side?
(DIR) Post #9m72h5dy7jlA8zb1Q8 by shaderphantom@awoo.space
2019-08-21T02:51:47Z
0 likes, 0 repeats
chrome's near monopoly is worse than the ie6 nightmare
(DIR) Post #9m72h5mTc6Z6ZNZogK by bhtooefr@snack.social
2019-08-21T13:46:11.751738Z
1 likes, 1 repeats
@shaderphantom I’m even gonna go further.IE6 holding the web back was a good thing, as it made the modern abuses of the web as an application platform, instead of as a document platform, much harder.
(DIR) Post #9m72udGGRfuaAixx5s by espectalll@mstdn.io
2019-08-21T13:48:56Z
0 likes, 0 repeats
@bhtooefr @shaderphantom I'm not sure about that, considering it was the time where Java and Flash boomedyou know how that went
(DIR) Post #9m73UnVLq28YMlGesS by bhtooefr@snack.social
2019-08-21T13:51:18.839951Z
0 likes, 0 repeats
@espectalll @shaderphantom Flash wasn’t capable enough to be abused like web apps are today, though. I mean, it was bad, but not in that particular way.(I’ll give you Java, though. That was the original Electron.)
(DIR) Post #9m73Xh9xsvyzYYe7X6 by espectalll@mstdn.io
2019-08-21T13:56:00Z
0 likes, 0 repeats
@bhtooefr @shaderphantom Flash was capable of running apps in very similar (but worse) ways to what HTML5/CSS3/ES6 allows you today, except buggier, more insecure and more annoying. And great news we got to where we are instead of Adobe Air, Silverlight or, indeed, more Java.Can't we just accept the problem isn't with web apps themselves but with the development culture and the holy grail of software that works as soon as you find it on any platform?
(DIR) Post #9m7fyT2AJDVrp5Btia by polychrome@cybre.space
2019-08-21T21:06:34Z
0 likes, 0 repeats
@espectalll @bhtooefr @shaderphantom flash was designed back where everything had to be a stupid plugin. :blobcatsip:
(DIR) Post #9m7g1WMwMjQp2FMeq8 by espectalll@mstdn.io
2019-08-21T21:07:11Z
0 likes, 0 repeats
@polychrome @bhtooefr @shaderphantom yeah, which ended up being worse than what we have now :blobcatsip:
(DIR) Post #9m7g4gMLg5PytAax84 by polychrome@cybre.space
2019-08-21T21:07:45Z
0 likes, 0 repeats
@espectalll :blobcatsip: !!