Danbooru

JavaScript Injection Bug

Posted under General

I can't seem to reproduce the bug outside of post/index, and even then it's only on certain pages (at random points), which leads me to suspect the cause is one of the posts. If anyone finds any contradictory evidence, please leave a comment.

A status update. The JavaScript isn't being injected from Rails, and (initially, after running tcpdump) Apache doesn't seem to be the cause either. We've also discovered that this bug appears even when you hit a static page like 404.html.

1