Are you ready to switch to HTML parsing permanently?

83.3% 65
1.3% 1
15.4% 12

78 Дата 14.04.2010 00:49

Форуми / Cotonti / Development / Опитування: A global switch to HTML parsing

Are you ready?

donP
#24119 15.04.2010 16:54
# Trustmaster : Koradhil means that an experienced hacker would make a special formed HTML page himself to submit unfiltered POST data, so server-side filtering with HTML-purifier is still required.
So we have to filter ALL contents? I was hoping we only had to filter pages/forums fields when submitting them, to speed-up HTMLPurifier process calling it only at submitting moment, not to filter all HTMLoutput content at displaying moment... :/
Why we couldn't make a security gate prohibiting the inclusion of HTML code except through Cotonti core files (from a regular logged user passing through HTMLPurifier)?

Added 13 hours 7 minutes later:

I think we would put this topic sticky and send a massPM or mail newsetter to reach all Cotonti users and asking them about this important argument...
in [color=#729FCF][b]BLUES[/b][/color] I trust

Відредаговано: donP (16.04.2010 06:05, 15 років тому)