How Random Babbling Becomes Corporate Policy (t3knomanser) wrote,
How Random Babbling Becomes Corporate Policy

Firefox and Greasemonkey

I'm a big fan of the Greasemonkey plugin. It's definitely a power-user feature, and a walking security flaw. Greasemonkey, for those not familiar, allows you to run your own custom javascripts on the pages that you visit. This can be very powerful- I've written several that address certain annoyances I might other wise have to deal with- like the crappy color scheme on the new FARK. My own javascript runs and replaces it.

Here's the thing that I noticed though- I can use javascript to add references to other javascript files. For example, I can write a script that tells the page to append new <script> tags. This loads, and executes, the script contained in those files.

I'm not sure what advantage this has. It could be used to make a self-updating Greasemonkey script- by simply changing the files on the server, every user that uses the script would now benefit from it. The obvious downside is that this newly loaded script could be changed on the fly- without the user's consent. It still runs in a sandbox, but I can easily use DOM objects like the IFrame to break out of it and do... well, nasty nasty things.

I think though, a sever-side GM script could be really useful for multi-user applications. Perhaps I'll write my client-side loader to do some basic validation and force the user to see the script, or verify a digital signature or something. I'll have to poke around on the GM and Firefox APIs to see if that's feasible.

One use that I'll have even before adding the security is for pushing scripts between home and work- only one script needs to be kept up to date, as opposed to a dozen.
Tags: geek, programming

  • Strange Things People Say About Me (to my face)

    Recently, I've been at the center of a trend. That trend is complete strangers asking me "Are you ____?" A quick summary. For example: Are you…

  • Writer's Block: If I could find my way

    -10,000 years, at minimum. Tomorrow is always better than today, especially when you can't fact-check.

  • Bob Morlang

    When I was working at Tri-Mount, we had these camp trucks. They were army surplus, and while they could take a beating, they only sort of worked. And…

  • Post a new comment


    Comments allowed for friends only

    Anonymous comments are disabled in this journal

    default userpic

    Your IP address will be recorded