![]() |
3.01 vb 3.0x html allowed?(NOT A BUG) RP 3.01 Vbulletin 3.0.x I am not sure if there is something wrong with my setup with reviewpost, I have altered one or two things but I am unsure if they would affect it or not but when I add a product in the extra fields I am able to insert html into those fields. I did change the settings in the database to a text field but I don't think or know if that would affect it at all. I can also insert html into the reply to a review, the quick reply and the full reply both accept it. That area I have not touched except for some language files. I have tried this both as an admin and as a normal member and the fields that accept html are the extra fields 1 thru 6 and the comments box on the full and quickl reply. Can someone check this on their setup to see if it's the same please. Thanks in advance Mike |
Yes you can enter html all day long but unless you enable the display of html it does nothing. I do not suggest the display of html but I did add a couple switch's in admin for user's who are diehard html fans. Do realize if you choose to allow users to do html that you risk XSS attacks |
Whoops kinda think we had a misunderstanding on the post. I have downloaded the latest build (as of today) and you cheeky monkeys :) have updated some of the code so html is no longer allowed. Last weeks version (Sept 3) did not have these changes in them. So yes, as far as the version I downloaded last week html was allowed in those fields and additional code has been added to showproduct.php, reviews.php, and editproduct.php to prevent this. :p (thats the stick out tongue smilie since my wife is none to thrilled with me spending the last two hours on the computer comparing files----why aren't you doing laundry she says) |
LOL laundry whats that. |
Quote:
|
No these switch's are not in Photopost. I have only personally coded Reviewpost thus far as Michael is the coder for Photopost. I posted in your other thread an example of what you need to do |
Quote:
How i can enable the display of html? I understand the risk, but i dont let the users (yet) to upload products. So it can be useful for me. Thanks. |
In reviewpost you have admin switch's to allow the display of html in products or reviews. By default you can already enter html we just dont parse it for display. By throwing the switch to allow display of html simply set the admin switch to yes |
| All times are GMT -5. The time now is 03:19 PM. |
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0