2009/6/4 Gregory Maxwell <gmaxwell(a)gmail.com>om>:
Restrict site-wide JS and raw HTML injection to a
smaller subset of
users who have been specifically schooled in these issues.
Is it feasible to allow admins to use raw HTML as appropriate but not
raw JS? Being able to fix MediaWiki: space messages with raw HTML is
way too useful on the occasions where it's useful.
Possible yes, sensible no. Because if you can edit raw html, you can inject
javascript.
-- daniel