[00:18:08] scp wiki is dope [00:18:10] [glabby](https://cdn.discordapp.com/emojis/1459557461596836016.webp?size=48&name=glabby&lossless=true) [00:56:24] And it's wikidot of all places. Big kudos to them for what they pulled off in that framework [00:58:29] does monobook and vector 2010 look good with a fixed width design? [01:05:53] still waiting for the day we will have custom html blocks [01:06:05] man if only the widgets thing wasnt a security risk [01:35:50] extremely loud incorrect buzzer goes off [01:36:26] The SCP and Backrooms fandoms are pure peak. 🧠 [06:51:45] μ•ˆλ…•ν•˜μ„Έμš” [06:51:56] ν•œκ΅­μ–΄ λ˜μ‹œλŠ” λΆ„ μžˆλ‚˜μš” [07:28:44] [1/2] https://www.mediawiki.org/wiki/Extension:Mustache [07:28:45] [2/2] Now we do (have a candidate extension) [07:39:26] I haven’t done a proper look but is it stable enough that I could theoretically add to a production farm? [07:42:20] It works on my local testing environment. That's all I can promise besides what I said in https://discord.com/channels/407504499280707585/1006789349498699827/1481557854245879909 [07:44:15] It's missing some features and will probably undergo more changes, but I don't think there will be some bad backward-incompatible change (besides those mandated by sec issues, of course). [07:44:52] Ooh's and aah's at the discord chat [07:45:07] With that said, I would recommend letting as least one sec expert have a quick glance over the whole thing to make sure there are no egregious problems. [07:45:29] [1/2] Also I was going to ask about this but apparently MH has `script-src 'unsafe-inline'` in CSP [07:45:29] [2/2] https://cdn.discordapp.com/attachments/615786602454581249/1481558737054466068/Screenshot_2026_0312_144440.png?ex=69b3c098&is=69b26f18&hm=a7d8c39fa8525de3ec18ee59768092bdfe7dd7db8b3aa09bec3d0ae7094ca9d4& [07:48:20] Yeah looks like we have `'unsafe-inline' 'unsafe-eval'`. Perhaps some important extension uses it, so we have to use it too... [07:53:04] I guess removing 'unsafe-inline' also breaks custom JS that works by embedding a script tag post-render [07:54:16] [1/7] Current TODO: [07:54:16] [2/7] ``` [07:54:16] [3/7] Write about window.RLQ in docs [07:54:16] [4/7] Validate the correctness of Mustache template on save in addition to security [07:54:17] [5/7] Explore CM6 options [07:54:17] [6/7] ``` [07:54:17] [7/7] I'll probably think of more in future days. [07:56:29] Reviewing this extension wouldn't be easy because it's 500+ lines of PHP excluding tests. Pretty short for an extension but longer than anything I've written. The review would be easy if the focus is on avoiding Widgets-style RCE but much harder if the goal is to stamp out as many XSS patterns as possible. [08:12:13] [1/5] bro [08:12:13] [2/5] https://cdn.discordapp.com/attachments/615786602454581249/1481565464558833704/1.jpg?ex=69b3c6dc&is=69b2755c&hm=08483639c823ed631cbd70557eb33c8bc9f63b9bf9c9f24ded0a084f9c87db30& [08:12:14] [3/5] https://cdn.discordapp.com/attachments/615786602454581249/1481565465007489176/2.jpg?ex=69b3c6dd&is=69b2755d&hm=c5ed5fe67ab4c36d9c6fddf708b52bc31c0513b5731da26e629b17c5b7823040& [08:12:14] [4/5] https://cdn.discordapp.com/attachments/615786602454581249/1481565465372266517/3.jpg?ex=69b3c6dd&is=69b2755d&hm=066dc8e64af663b78f351e799e6f8c3fde239b5a2d19bca68ba4fb27e11543e4& [08:12:14] [5/5] https://cdn.discordapp.com/attachments/615786602454581249/1481565465732972565/4.jpg?ex=69b3c6dd&is=69b2755d&hm=32423ee1c10c6fb1ddba4875d5e619fa3acca26975c30d4cfdd80d4d7d7f0247& [08:14:22] https://voidstorm.miraheze.org/wiki/Guardian [08:14:44] Woah it automatically fills the embeds now?? [08:15:03] No more manually filling SEO stuff???? [08:20:23] "All miraheze wikis are design slop" - this guy [08:20:48] Can't have shit man miraheze doesn't have fuckass ridiculous styling guidelines 😭 [08:40:13] https://www.mediawiki.org/wiki/Extension:TextExtracts prolly [09:18:52] Have I missed any drama as of late? Have not been looking at the history for the past year or so [09:25:56] is that yours [09:43:21] Y-yes [09:46:56] How Awesole [09:47:17] However it is not awesome that you didn't use refreshed [09:47:27] Prepare for your execution [09:48:09] Noooo 😒 [11:03:07] Use the refreshed skin i swear in your blood race it's good [14:11:24] the most insane claim ever 😭 [14:12:59] what is your lest fave skin? [14:27:12] insane claim? it's a good skin wym [14:45:35] cologne [14:45:41] https://tenor.com/view/cat-gif-22093205 [14:53:08] modern and cologne [15:00:14] """""modern""""" [15:05:36] i guess it was modern for it's time lol [15:14:26] I think the Mask skin is rather outdated... tbh I dislike any non mobile adpative skin [15:38:08] real [15:38:13] checks it out [15:38:39] ehhhhhhhh [15:38:40] idk [15:38:54] [1/2] what the fart REAL [15:38:54] [2/2] https://cdn.discordapp.com/attachments/615786602454581249/1481677875383111881/image.png?ex=69b42f8d&is=69b2de0d&hm=a1c045a7106be881e6cf55933bcc0a0e3e767270009e4ca3c5a4cdcf89846299& [15:39:57] ! [15:40:10] LEGO [15:40:18] yeah [15:40:22] lego is `peak` (i only played lego games not actual lego) [15:45:48] i guess you hate vector 2010 lol [15:53:56] can we all collectively hate the new version of vector plzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz 🀩 [15:58:34] I dislike old!Vector [15:59:02] I like 2022!Vector [16:23:41] πŸ’₯ [16:27:24] I do not mind Cosmos but not 100% my taste [16:27:39] <_chrs_, replying to tangoer_man> [1/2] would people find it useful to have a gadget which provides support for wikidot style raw html blocks? [16:27:40] <_chrs_, replying to tangoer_man> [2/2] (i.e., you need no special permissions to make them, because they run in a secure iframe) [16:28:16] probably [18:03:19] I hate cosmos with passion [18:03:24] reminds me of fandom [18:03:39] I mean, I would not use it, but not a skin I hate [18:38:39] My guy my guy [18:38:57] that's the entire purpose of that skin lmao, to replicate Fandom's (then Wikia) Oasis skin [18:39:19] that failed on doing so cause it's so ugly [18:39:42] got to give credit to Cosmic though, it was his first skin [18:42:16] Cosmos can look quite nice if you CSS it heavly [18:42:25] Cosmos can look quite nice if you CSS it heavily [19:01:20] cosmos is fine as a skin, though I do prefer vector 2010 with beautiful colors like on weird gloop wikis, most wiki.gg wikis, and some miraheze wikis [19:52:05] [1/2] Fire [19:52:05] [2/2] https://cdn.discordapp.com/attachments/615786602454581249/1481741592397091018/C3574587-7ED5-4EDB-9D16-B8FC3E4E6C36.jpg?ex=69b46ae5&is=69b31965&hm=1e76fa5df58b9a8aeac85c1010beda19e6e88b223bfd81f3edcd75785ba7e48d& [20:30:21] Would be interesting if Cosmos has a config options that loads a bunch of CSS to make it look like https://worldtriggerwiki.com