Ticket #1509 (closed defect: fixed)
Whitelist of allowed HTML tags doesn't work in Kupu
| Reported by: | hans | Owned by: | jukka |
|---|---|---|---|
| Priority: | blocker | Milestone: | |
| Component: | generic | Version: | |
| Keywords: | Cc: | ||
| Time spent: | Time remaining: | ||
| Time planned: |
Description (last modified by hans) (diff)
I understand that we have a whitelist of allowed HTML tags in Kupu. According to UI the following tags are allowed: <h2>, <p>, <br />, <pre>, <ul>, <ol>, <li>, <a>, <i>, <b> (some allowed tags such as <sub>, <sup>, <table>, <td>, <tr> are missing from that list).
I don't understand how users are able to input their own JavaScript?, CSS and form elements... I don't want LeMill look like a MySpace? :)
http://lemill.net/content/fluxogramas/view
http://lemill.org/trac/attachment/ticket/1509/fluxogramas.png?format=raw
Attachments
Change History
Note: See
TracTickets for help on using
tickets.
