Recent Topics

1 Nov 10, 2007 13:17    

My b2evolution Version: 2.x

There's more way to skin a cat.
I wanted to use "onclick" in a post and got the usual "what the F#@&k do you think your doing" message.
I didn't want to turn javascript on so I added "onclick" to the conf /formatting $allowed_attributes = array for a ( transitional)

So without having to resort to "allow Javascript" i'm able to use limited JS in posts. This may also open the opportunity for toggles of show/hide etc

Am I exposing my self to a million exploits or am I safe?

Example is a pop up for YouTube
http://wow-factor.com/index.php/column-a-or-b

2 Nov 11, 2007 10:53

As a follow up, what are the pro's n con's of adding to allowed attributes?
One thing I would like to do is add "id" to allowed attributes for DIV?

I can see how this could get out of hand but don't know the implications good or bad.

3 Nov 11, 2007 11:54

you can add id & style by changing the setting in conf/_formatting.php

# Set this to true to allow id && style as core attributes for posts
$posts_allow_css_tweaks = true;

¥

4 Nov 11, 2007 12:01

Thanks mate, now I understand what that really means

5 Nov 11, 2007 12:20

What it really means is that I got fed up of editing _formatting.php every upgrade to manually add the attributes ;)

¥

6 Nov 11, 2007 13:21

Your not wrong there.... You almost have to keep a diary on your formatting fiddles :)

7 Nov 11, 2007 14:49

Hehe lawlz. I already have a few files with edits strongly noted so I don't forget. At least it is fewer now :p

Just keep the comments stuff to not allow, that'll keep the commenters out of the risky elements and attributes.

8 Nov 11, 2007 14:50

Just keep the comments stuff to not allow, that'll keep the commenters out of the risky elements and attributes.

absolutely


Form is loading...