FUDforum
Fast Uncompromising Discussions. FUDforum will get your users talking.

Home » FUDforum Development » Bug Reports » 2.5.0RC4 - Announcement System
Show: Today's Messages :: Polls :: Message Navigator
Switch to threaded view of this topic Create a new topic Submit Reply
2.5.0RC4 - Announcement System [message #10649] Fri, 06 June 2003 04:06 Go to next message
Xodnizel   United States
Messages: 73
Registered: May 2003
Karma: 0
Member
In the announcement system, under the list of eannouncements, the Subject and Bodies aren't escaped for html. This really needs to be done, because fudforum truncates the body when it's displayed in that format, leading to some unpleasant results(tags aren't closed, and tags can be interrupted). Here is the HTML from the generated page, if you're curious as to what happens:

<tr bgcolor="#ffb5b5"><td>Introduction</td><td>& lt;font size="2" face="Verd...</td><td>June 6, 2003</td><td>December 31, 1969</td><td>[<a href="admannounce.php?edit=1&">Edit</a>] [<a href="admannounce.php?del=1&">Delete</a>]</td> </tr>


The starting text of my announcement is:
<font size="2" face="Verdana, Arial, Helvetica, sans-serif">
(That's where the <font ...> bit comes from in the code quote.)
Re: 2.5.0RC4 - Announcement System [message #10658 is a reply to message #10649] Fri, 06 June 2003 12:38 Go to previous message
Ilia is currently offline  Ilia   Canada
Messages: 13241
Registered: January 2002
Karma: 0
Senior Member
Administrator
Core Developer
The announcments are intentionally not sanitized for HTML to allow the admins to include HTML in their announcment. This is not a bug but rather a feature to allow for greater functionality.
On the admin control panel I do see your point and will add HTML sanitation there.


FUDforum Core Developer
  Switch to threaded view of this topic Create a new topic Submit Reply
Previous Topic: 2.5.0RC4 PMs
Next Topic: 404 not found for www icon in membership listing
Goto Forum:
  

-=] Back to Top [=-
[ Syndicate this forum (XML) ] [ RSS ]

Current Time: Sun Nov 24 20:13:30 GMT 2024

Total time taken to generate the page: 0.02428 seconds