Missing iframes
In case you missed this. I am not a happy camper right now.
this impacts you if you have any of the following:
- embedded google maps
- videos that were manually embedded
- reabird listing
I have 63 posts to edit. I've done 10 so far.
It has come to our attention that a few of you may be missing iframed HTML from your blog posts. We've estimated that less than 1,000 members have been affected. Only those members who have manually embedded an iframe in their posts between January 9th 2013 and June 20th may have been affected. No profiles or signatures were affected.
An iframe is an HTML document embedded within another HTML document. So a video or widget embedded on a blog post could be an iframe. Essentially it could look something like this: <iframe id="ifrm" src="demo.html"></iframe>
Here's what happened; in January we introduced a new software library, Loofah, into AR to prevent Cross-site scripting. Cross-site scripting is a type of code found in Web applications that allows code from one site to display on another site. This type of code is often exploited by spammers and evil types and the goal was to shore up the security of ActiveRain.
When we released the deploy last week, it caused some blog posts to be stripped of their iframes. Loofah had been overly aggressive; stripping iframes from blogs posts. You didn't immediately see this because what was being written into our memory cache was different from what was being permanently stored in the database. Once the posts aged out of the cache, it was retrieved from the database and displayed without its iframe.
We are very sorry and sincerely apologize for this situation.
The good news is we have replaced much of the lost information so most of you won't even miss a beat. Another positive is that IT has fixed Loofah so it will not attack iframes going forward. This new Loofah has been tested and verified with our IT team. For those members that are missing a video or other iframe piece within your blog post, you'll need to enter it once again and can do so in 4 steps.
We have done our best to think outside of the box and retrieve as much of the lost footage as possible. We sincerely apologize for this situation and inconvenience to those affected.






Comments (6)Subscribe to CommentsComment