kane_magus: (Default)

Link to comic.

Link to blog.

This is another one of those "the associated blog is actually of more interest to me than the comic" comic posts.

(EDIT) Yet another post to fall victim to that bizarrely still existent "can't have 'Hidden ' in the subject line" bug. (/EDIT)

Date: 2026-04-09 10:23 am (UTC)From: [personal profile] andrewducker
andrewducker: (Default)

What a weird bug. Have you reported it?

Date: 2026-04-09 04:45 pm (UTC)From: [personal profile] andrewducker
andrewducker: (Default)

Wow. That's an impressive amount of time for it to live on the back burner. I wonder what crucial piece of functionality is entirely reliant on it.

Date: 2026-04-10 10:32 am (UTC)From: [personal profile] goldpseudo
goldpseudo: (Default)

I'm not an HTML expert, but looks like they're failing to escape quotation marks. So, like, the link is getting encoded like this:

<a title="Penny Arcade - "Hidden Mechanics"" href="https://kane-magus.dreamwidth.org/1773235.html">

Which basically means the first quotation mark closes the title= attribute and it reads the rest of the "quote" as new attributes. And in this case, hidden means, well, hide it.

Also, this means that it's actually affecting every single title that has a quotation mark in it; the title= attribute is what should be showing up in the mouseover text for the link itself. It's only obvious with hidden because hidden is also an attribute that has a visible effect, but most of your quoted titles are just random words that mean nothing in an HTML sense (e.g. this post shows the proper title on mouseover, but this one does not. But since invisible, baby and meters aren't keywords in HTML, it just… ignores them.)

Also, whole thing would probably break if you ever had a title with only one quotation mark in it.

This also feels super-vulnerable to injection attacks. I bet you could do some serious damage with something along the lines of setting your title to This is a safe link" href="http://notavirus.totallylegitsite.xyz". Y'know, if you're into that sorta thing.

Edited Date: 2026-04-10 10:33 am (UTC)

Profile

kane_magus: (Default)
kane_magus

April 2026

S M T W T F S
    1 2 3 4
5 6 7 8 9 10 11
12 131415 16 17 18
192021 22232425
2627282930  

Most Popular Tags

Page Summary

Style Credit

Page generated Apr. 23rd, 2026 02:18 pm
Powered by Dreamwidth Studios