- Notifications
You must be signed in to change notification settings - Fork5.5k
Open all files with/files path except for.html and .svg`#2449
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Conversation
gnestor commentedApr 27, 2017
@takluyver Can you review? |
takluyver commentedApr 28, 2017
@minrk@rgbkrk do you know of any file types other than html and svg that we should be displaying in the iframe? |
minrk commentedApr 28, 2017 • edited
Loading Uh oh!
There was an error while loading.Please reload this page.
edited
Uh oh!
There was an error while loading.Please reload this page.
It's probably best to avoid a 'not_safe' blacklist, because it's easy to miss things (like the many synonyms for html) instead having a 'safe' list for things that can be trusted to be displayed raw. It seems like it makes more sense to specify a list of things thatdon't work in the iframe (are there examples other than PDF?) |
gnestor commentedMay 6, 2017
I updated so that |
takluyver commentedMay 8, 2017
Isn't that the same blacklisting approach just with the name 'viewable' in place of 'not_safe'? I see |
gnestor commentedMay 31, 2017
I have updated this PR. The way it works now:
|
Closes#2404