Yes, I’m not arguing or anything, I forgot to mention I appreciated the added context you provided. Just wanted to further expand on it for those wanting to get more context, as it seems to be a lot of people in the thread that didn’t read the article
It’s worse than that. Until Lemmy is more mature, I would reccomend using the lite version of Lemmy, the JS-free version, for sake of client side security. Alternatively, or as an added point of security, the front-ends themselves should implement more sanitazion themselves. I’m willing to spend some free time vulnerability testing, but I would need a dedicated sand-box for that.