foxfirefey: A fox colored like flame over an ornately framed globe (Default)
foxfirefey ([personal profile] foxfirefey) wrote in [site community profile] dw_suggestions2009-09-15 06:52 pm

Open up s2id viewing capabilities

Title:
Open up s2id viewing capabilities

Area:
styles

Summary:
If all of a style's layers are public, anyone should be able to use the s2id capability to view it on any journal, in addition to the current s2id viewing capabilities.

Description:
I think the current s2id viewing restrictions were originally implemented on LJ at a time when there were paid only styles, and it was meant to discourage abuse of making all your links to your journal use that style you didn't have access to or something. (I could be wrong!)

But, on DW we don't have any paid only styles, and additionally all users have full (if sometimes very limited) access to the advanced S2 customization area, so I think this restriction makes less sense.

It would help out with style testing if people could use a style ID to view any other journal. I *think* if it was limited to styles that only had public layers, then it wouldn't accidentally expose private information someone's possibly coded into the style.

Poll #1282 Open up s2id viewing capabilities
Open to: Registered Users, detailed results viewable to: All, participants: 26


This suggestion:

View Answers

Should be implemented as-is.
19 (73.1%)

Should be implemented with changes. (please comment)
0 (0.0%)

Shouldn't be implemented.
0 (0.0%)

(I have no opinion)
7 (26.9%)

(Other: please comment)
0 (0.0%)

lastdance: (Default)

[personal profile] lastdance 2009-09-18 12:07 am (UTC)(link)
I would love this option.
afuna: Cat under a blanket. Text: "Cats are just little people with Fur and Fangs" (Default)

[personal profile] afuna 2009-09-18 02:44 am (UTC)(link)
As it was explained to me, the limitation was introduced so you couldn't create a custom style for one paid account, and then embed a bunch of free accounts with an ?s2id created for that paid account.

With the lifting of limitations on the advanced customization area, though, the limitation seems much less useful.
turlough: castle on mountain top in winter, Burg Hohenzollern ((mcr) bob approves)

[personal profile] turlough 2009-09-18 01:57 pm (UTC)(link)
As someone who occasionally makes layouts for others I would love to have this!
adalger: Earthrise as seen from the moon, captured on camera by the crew of Apollo 16 (Default)

[personal profile] adalger 2009-09-18 06:33 pm (UTC)(link)
This would make it sooooo much easier to help other people with their styles, too! Support, [community profile] style_system, ...
liv: Stylised sheep with blue, purple, pink horizontal stripes, and teacup brand, dreams of Dreamwidth (sheeeep)

[personal profile] liv 2009-09-19 03:53 pm (UTC)(link)
I would basically love this, but I think that the LJ restriction is a security thing, not a prevent abusing paid account styles thing. If someone manages to get round the limits on S2 and create a style that does something dangerous, eg steal cookies, if you can only view on the person's own journal, you can only get cookies from that subdomain. But if you can just add ?s2id= to any journal, you can view other people's journals in your malicious style. If I'm wrong about that then I am in favour of this suggestion. But my memory is that the restrictions are related to the way that subdomains are fenced off from eachother, so introducing the feature may be a potential security problem.