Daily Shaarli

All links of one day in a single page.

May 4, 2022

Yes, fun browser extensions can have vulnerabilities too! | Almost Secure

Messages sent through the window object can be intercepted by every source, and every source can emit messages.

Fixes:

  1. No more HTML injection: The talk bubble no longer allows injecting HTML code.
  2. Check origin: The synchronization script checks message origin and rejects messages coming from other websites.
  3. Restrict message range effect : The messages allowed by the synchronization script have been restricted to things like “Change hat,” no longer allowing changing arbitrary settings.
Apps.education.fr Accueil

Apps.education.fr est une plateforme développée au sein de la direction du numérique pour l'éducation pour proposer les outils essentiels du quotidien à l'ensemble des agents de l'Éducation nationale.

On retrouve: peertube, Etherpad, CodiMD, Mastodon, Nextcloud, ....

Super !

Scribe - CEMEA

Retranscribe audio or video to text 👍‍

Des Ukrainiennes victimes de viol se heurtent à la loi anti-IVG polonaise – Libération