Tag Archives: Whiteboard

About Kerika’s Whiteboards and Canvases.

Guarding against XSS/code-injection

It’s possible to copy-paste text into a Kerika Chat message, and there are legitimate use-cases for this: for example, a developer may ask a question to a coworker who replies with a code snippet.

Kerika handles code in chat messages by storing two versions of the message: as plain-text, and as the original format. When a chat message is displayed, the original format is used but not executed, which means the embedded code is visible, but doesn’t run in the browser. This makes it easy and safe to share code snippets through chat messages.

While making this improvement, we went through all the places where a user can type in text, Card Title and Description, Board Name and Description, Tag, Attachment Name, etc. to make sure we are guarding against malicious code injection.

Embedding a Twitter feed in a Kerika Whiteboard

Here’s a feature that we suspect most people probably don’t know about: you can embed a live Twitter feed on any Kerika Whiteboard.

While working on a Whiteboard, click on the Add Web Content button that appears in the left-hand toolbar, towards the bottom:

Adding Twitter feed to Whiteboard
Adding Twitter feed to Whiteboard

You can reference Twitter feeds with a simple “@” symbol: you can add Kerika’s Twitter feed just by typing in “@Kerika”.

The Twitter feed appears as a live object on your Whiteboard:

Live Twitter feed on Whiteboard
Live Twitter feed on Whiteboard

You might find it convenient to rename the URL to something more descriptive: you can do this by selecting the object and using the right-mouse button to get this menu:

Renaming Twitter feed for Whiteboard
Renaming Twitter feed for Whiteboard

Embedded Twitter feed on Kerika Whiteboard
Embedded Twitter feed on Kerika Whiteboard


We have added support for Google Team Drive

We have long had a deep, excellent integration with Google Apps: you can sign up with your Google ID and have all your Kerika-related files stored in your own Google Drive, where you can access them independently of the Kerika app.

We are now taking that one step forward, with seamless integration with Google Team Drive.

Google Team Drives are shared spaces where teams can easily store, search, and access their files anywhere, from any device.

Unlike files in My Drive, files in Team Drive belong to the team instead of an individual. Even if members leave, the files stay exactly where they are so your team can continue to share information and get work done.

Team Drives is available on G Suite Enterprise, G Suite Business, or G Suite for Education editions.

You don’t need to do anything different: the integration is built-in with the latest version of Kerika (and, since we are software-as-a-service, everyone always uses the latest version of our product!) and the integration is seamless.