My gift to the rustdoc team

81 points by winter


apetros

I am a little surprised that anyone publishing to docs.rs can inject an arbitrary script in there. I am generally in favor of supporting HTML customization and the header-include feature is very cool but this does seem like a reasonable place for a script-src 'self' CSP. There might be other countermeasures I'm not aware of, though (ToS, etc.), and obviously they do have to police malicious crates anyway.