Slashdot slipping an iframe in item <description>?

I’m not sure this is a bug, but I thought it was weird.

Opened a Slashdot story and got a cookie-consent banner (“Accept All” / “Reject Optional”) rendered inside the article pane.

I got worried at first that it was some security issue, and I guess it sort of is from a tracking perspective - but it turns out Slashdot ships an in every item’s :

curl -s Slashdot | grep -c iframe → 15, across 15 items. The feed itself has zero script tags, but that embed URL returns their full page, including their consent manager. So the banner is Slashdot’s doing.

It only shows on the feed-content path, not Reader View, which fits — extracted articles don’t carry the iframe.

I suppose it makes sense as a rendering tradeoff - I guess this allows for youtube downloads and social embeds and the like, but wanted to check in regardless. I pointed an LLM at it and have a small body sanitizer and some tests I could submit if there’s an appetite for a PR, but wanted to take temperature first.

I’ve always had a white box at the bottom of every Slashdot feed item (noticeable only when using dark mode) and it blinds me when I’m catching up on my feeds before bed. I hate it and wish it would go away. I always assumed it was an add that was trying to be inserted, but based on your screenshot, it looks like you’re seeing a cookie notice. What I see is just a plain white box.

I just might not have noticed the white box before, and they just rotated the ad. I guess I’m in light mode most of the time. Still, feels icky.

For some reason I don’t see this — which type of account are you using?

Fix coming in the next build :+1:

1 Like

Sorry for the off-topic post:

It’s nice to see that so many others have remained loyal to Slashdot for about 30 years. I still read Slashdot, too.

1 Like

sorry, been moving/traveling and lost this…thank you! I’m on Feedly (and appreciate the slew of fixes there, I just found about 6 subscriptions that were somehow masked to just their site)

1 Like