[–] 36 points 1 week ago* (3 children)

I would support such a ban so long as there is some process to prevent it becoming a witch hunt.

I have personally already received one false accusation of using AI in this community and I wouldn't want to continue posting projects here if it becomes an atmosphere of suspicion.

  • source
  •  

    Can anyone provide a basic rundown of how Lemmy handles input sanitization?

    I ask because I want to know if it is necessary for lemmy userscripts to sanitize the content of comments for security purposes or if I can reasonably expect that this has already occurred.

    My specific concern is whether the innerHTML attribute of comments can still contain harmful scripts even after Lemmy's sanitization procedure.

    I am not very familiar with rust and it's not obvious to me from skimming the source code. Some of the git issues hint at it occurring server side while others in the ui?

    Questions:

    • Where does input sanitization occur?
    • Does the sanitization simply prevent injection or does it further more reject the comment/entirely remove the script from comment/ban user etc?
    • Can posts and comments still contain potential threats via a userscript vector?
    • How is sanitization handled with regard to federation? ie; are comments received from federation also sanitized despite not being input directly by the user on the receiving server?

    I know it would be good practice to just sanitize it in the userscript anyways but I would still like to know what's happening on the Lemmy side.

    [–] [S] 4 points 2 weeks ago (3 children)

    I agree in principle although I consider this script to be a tool of adversarial interoperability; it's purpose is to extricate information from twitter to lemmy. Also it doesn't actually interact with twitter directly, only with nitter front ends.

  • source
  • parent
  • context
  •  

    It adds copy and quote buttons to each tweet on nitter instances (eg: xcancel).

    Each button copies the tweet and formats it into commonmark markdown as used by Lemmy. Copy includes links to any attached videos or images.

    Copy Demonstration

    It's FOSS @Itsfoss
    Sep 7, 2026 11:33 AM UTC

    Two weeks after X Corp's legal letter forced the project offline, Nitter says it will continue.

    itsfoss.com/news/nitter-retu…

    ||

    | [Ӿ] [ℕ] [🏛] |

    Quote Demonstration

    Two weeks after X Corp's legal letter forced the project offline, Nitter says it will continue.

    itsfoss.com/news/nitter-retu…

    The formatted markdown is then copied to your clipboard.

    You can install it using a userscript browser extension such as Firemonkey or violentmonkey.

    The user script is available at Greasyfork.

    https://greasyfork.org/en/scripts/595501-xtractor

    To add additonal nitter instances simply add the following line;

    // @match *://nitter.net/*

    Except with the url of the instance of your choice.