Comment 1 for bug 547902

Revision history for this message
Ray Merrill (rmerrill) wrote :

The ability for user's to embed code/script within their
views (web pages) is not really practical. Sites like
Facebook and MySpace used to let people do so because it
makes for such a greater experience and capability ...
unfortunately it opens up security and virus concerns that
are not really acceptable, particularly to implementations
that are going to being connected to district and university
databases.

With that said the ability for site, institution, and
certain types of groups to embed javascript within their
views (web pages) is a really good thing, as administrators
can and should be trustworthy to avoid mischief or malicious
activity.

Also, as an alternative, we could follow the same approach
that MySpace and Facebook have in allowing for individuals
and groups to create plugin applications (for Mahara, it
would be plug in blocks). For MySpace and Facebook, such
applications undergo a technical code review to ensure they
are trustworthy.