Re: Re: Re: Tiki 1.8.2 and URLs

posts: 2881 United Kingdom

> actinic:
> > Damian:
> > Yes all nasty script, object, embed, and others get removed now. Maybe in 1.8.3 we can have some per form checkbox that requires activation before submitting, certainly it wouldnt be a global option!
> The problem with this is that the default tiki templates make use of Javascript in good and useful ways (expanding items on the application menu for example). Maybe the stripping of tags needs to be more intelligent, only allowing tags with known "good" attribute values.

The "cleaner" only affects the javascript and things that you submit through the tiki interface, those JS bits that are called from the tpl files are not affected.

Javascript is such a huge language, you would have a hard time defining whats good there and what isnt.


Upcoming Events

No records to display

Why Register?

Register at tiki.org and you'll be able to use the account at any *.tiki.org site, thanks to the InterTiki feature. A valid email address is required to receive site notifications and occasional newsletters. You can opt out of these items at any time.