You can go ahead and add “systemic XSS vulnerabilities” to why I’m not on Lemmy, what the heck.
In addition to the sidebar and, potentially, the markdown interpreter, archiving a Lemmy post and accessing it changes the domains to web.archive.org. Yikes.
Lemmy is probably gonna need an audit at this point.
Add can’t log out to the list, still unfixed FFS. So even if you know your cookies can be stolen, good luck trying to stop them from being used.
Credit: lemmy [dot] world/comment/1071591
Edit: Oh, in another issue, someone else last week fixed the part where error pages show your tokens. An audit is definitely in order.