From 423c8043a6ef54927c7890f3dd941acca4d6845f Mon Sep 17 00:00:00 2001 From: Jon Atkins Date: Sat, 7 Feb 2015 00:09:57 +0000 Subject: [PATCH] restore the 'confirm' prompt on server-supplied javascript to execute i have some minor concerns about some of the code changes in the 6th Feb 2015 stock site update, so may be better left in for now fixes (kinda) #941 --- code/botguard_interface.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/code/botguard_interface.js b/code/botguard_interface.js index 0a6fdccf..b20a1d3b 100644 --- a/code/botguard_interface.js +++ b/code/botguard_interface.js @@ -114,8 +114,8 @@ iitc_bg.process_key = function(key,serverEval) { // (but this is only when we don't send the correct params to the server? no reports of this code triggering yet...) try { console.warn('botguard: Server-generated javascript eval requested:\n'+serverEval); -//debugger; -//if (!confirm('The server asked IITC to run (eval) some javascript. This may or may not be safe. Run and continue?\n\nScript:\n'+serverEval)) { console.error('server javascript eval cancelled') } else +debugger; +if (!confirm('The server asked IITC to run (eval) some javascript. This may or may not be safe. Run and continue?\n\nScript:\n'+serverEval)) { console.error('server javascript eval cancelled') } else iitc_bg.evalFunc(serverEval); console.log('botguard: Server-generated javascript ran OK'); } catch(e) {