I have another idea on the back of my mind, but I think I need feedback before I touch the relative code.
At the moment one can write anything in the news box. This is nice (images, videos!), although it can lead to serious trouble. I have already fixed the nasty kind, but accepting html and javascript is still a problem.
I'd like to filter more stuff then, but without cutting useful features. I was thinking about:
At the moment one can write anything in the news box. This is nice (images, videos!), although it can lead to serious trouble. I have already fixed the nasty kind, but accepting html and javascript is still a problem.
I'd like to filter more stuff then, but without cutting useful features. I was thinking about:
- filter all html stuff (I can either remove it silently or make it appear as inactive code)
- accept links and do smart things: e.g., if one sends a youtube link, the video gets embedded, same with images.
Would that work? Is there anything else that would make sense?
Maybe some text formatting such as *bold text* or ZCTxxx becoming links to the track page?