Uploaded image for project: 'XWiki Rendering'
  1. XWiki Rendering
  2. XRENDERING-27

Require a safe way to disable html macro

    XMLWordPrintable

Details

    • New Feature
    • Resolution: Solved By
    • Major
    • None
    • Rendering in the platform
    • Macro - HTML
    • None
    • disable html macro
    • N/A
    • N/A

    Description

      http://dev.xwiki.org/xwiki/bin/view/Design/NewRenderingArchitecture
      makes mention of disabling the HTML macro, but it appears that there is currently no safe way of doing this (simply removing the xwiki-core-rendering-macro-html-<version>.jar will likely break XWiki)

      The use case for wanting to disable the HTML macro is essentially referenced here
      http://massol.myxwiki.org/xwiki/bin/view/Blog/XWiki

      I have 2 requirements;
      1) explicily NOT allow javascript to be entered (to help prevent malicious scripts)
      2) allow only a specified syntax, that is, do not allow users to enter html elements (primarily to keep content in the same format)

      Attachments

        Issue Links

          Activity

            People

              vmassol Vincent Massol
              cmp Chris Phelan
              Votes:
              2 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: