Re: A JS script has been blocked by GNU LibreJS on homepage website

Tina Petzel <[email protected]>
Newsgroups gmane.comp.gnu.lilypond.general
Message-ID <[email protected]>
Hi Ngô Phú Hiển,

> Like the title said, there's a JS script on the homepage website that is not
> satisfied with the GNU LibreJS's free script rules (The script uses a reserved
> object XMLHttpRequest).
> 
> The page is still usable actually. But i feel quite bad seeing this. I hope it
> will get fixed soon.

I think this is not really the place for fixes to LibreJS.

The code in question is responsible for dynamically loading the content of

https://lilypond.org/tweets.xml[1]

into the Pondings section (so dynamic loading of small blog-like postings). The code in question is 
trivial and thus not copyrightable (it is literally “Load this xml file, get all tweets, extract a 
random one and write the text into the pondings div”). Thus LibreJS should not care about it. If 
LibreJS does not recognize this script as trivial this is a flaw in the detection logic of LibreJS.

Our possibilities here are:

- Add a probably invalid license to the code section (invalid, as the code is too trivial to be 
copyrightable)
- Switch the whole website to some serverside dynamic loading. Afaik the whole Lilypond 
website is static. Not sure how high the motivation here is to switch it to PHP just to avoid 
LibreJS blocking an unimportant script.

Now, as already said, the problem is that since obviously this code does not have the complexity 
to justify copyright we cannot legally license it (not even under CC0). I also could not find a way 
to flag a piece of code as public domain for LibreJS, which would of course be quite simple.

So best place to take this to is LibreJS I think, and maybe ask the question why LibreJS would 
consider 9 effective lines of highly trivial code as copyrightable, and if there shouldn’t be a way 
to flag this is public domain.

Of course, arguable loading arbitrary stuff and injecting it into the website is not really a safe 
practice and is potentially an attack vendor (but then, it is the Lilypond website, there should not 
be much to attack anyway).

It also does not seem like this section of the Website is actually maintained — it has a total of 3 
tweets that all date back to 2013/2014. So I’d guess this was established once in that time and 
then never really maintained. Do we actually need/want this on the page?

Cheers,
Tina

--------
[1] https://lilypond.org/tweets.xml
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQS0sdUK2Lu8of48K2+FHhaCPe7BywUCaicTDwAKCRCFHhaCPe7B
yzTYAQCHN0BUNKe1l2z8erbdjLQbMxNuvHhucrhcBLuVv3uOrQD9HnHZ+J6ZsJfz
n21MACNzPIMypU/1Bn0XuNECP2d0jQY=
=FVVi
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.