Giter Club home page Giter Club logo

onebox's Issues

Allow the option to cache returns from websites

We want to be able to cache the return responses for certain oneboxes. This cache should pretty much be any key/value system that responds to fetch/write. Default should be an in-memory hash.

Better handle determining how to match urls to oneboxes

We want to have an easier time handling the matching of urls to oneboxes. We need to determine how to equate a onebox to a regular expression through a nice class level DSL.

In addition we want to use verbexpressions to write those regular expressions in the match setup.

Create yFrog onebox

matcher /^https?:\/\/(?:www\.)?yfrog\.(com|ru|com\.tr|it|fr|co\.il|co\.uk|com\.pl|pl|eu|us)\/[a-zA-Z0-9]+/

Why move matching url away from the onebox?

Though I think it was rather sloppy implemented in the previous version, I think it's a good idea to keep the code which matches the url close to the onebox conversion code. This way, you define in your onebox what urls you support, which is sort of a precondition for your code.

So I was wondering why the choice was made to move this away?

Write up a How-To for new architecture

Since we're introducing a new architecture for each OneBox it'll be nice to have a quick introduction on all the parts required for a new onebox.

  1. Creating the Engine object
  2. Creating the template (inline or file)
  3. (optional) Presenters for data
  4. (optional) Sanitizing/checking setup
  5. (optional) Setting up OpenGraph

We need a way to sanitize any URLs or text we render

While our current architecture, grabing data from the response of a resource and injecting that data into a handlebars template, avoids many types of attack there's a few known problem areas we don't cover:

  1. @markijbema pointed out that we encourage XSS by grabbing image src values
  2. There may be ways to inject running JS in any parts of the resource we grab
  3. The URL we are given might contain an XSS attack

Turn URLs into Oneboxes

We need a simple maintainable way to turn urls given to Onebox into their coorsponding onebox objects. This object should know what to do if the request fails (404, 500, etc), needs to be authenticated (401), or redirected (302). It should also know what a valid URL looks like and handle that correctly.

Usage of tabs and spaces

Just noticed this file while browsing around:

https://github.com/dysania/onebox/blob/master/lib/onebox/preview/amazon.rb

In ruby it's convention to use 2 spaces for indenting, but it looks like in this file (maybe others?) also tabs were used. I suspect this is due to editor configuration of one of the committers. Most editors can easily be configured to use spaces, for instance, for sublimetext config you could use this one:

https://gist.github.com/markijbema/5668813

(sorry if this comes of as pedantic, but in my experience having non-standard spacing leads to lots of merge conflicts later on, so better to fix it quickly)

Support for OpenGraph.

We want to handle open graph if possible as it avoids a lot of HTML parsing problems. Most websites support opengraph so we'll need a module that shares open graph behavior with Engine objects.

We should probably use intridea/opengraph.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.