-
Work Task
-
Resolution: Won't Do
-
Major
-
None
-
None
Some of the Descriptions for Datasets have html formatting (Bold, Italics, etc...).
What is our policy on allowing User content to have formatting?
If we allow formatting we should be dilligent about what type of formatting we allow. If we aren't a user can (untentinall or intenionally) ruin our page formatting by using some <div> blocks.
We could open our Users to Cross-Site Scripting (XSS) attacks:
http://en.wikipedia.org/wiki/Cross-site_scripting
What is our policy on allowing User content to have formatting?
If we allow formatting we should be dilligent about what type of formatting we allow. If we aren't a user can (untentinall or intenionally) ruin our page formatting by using some <div> blocks.
We could open our Users to Cross-Site Scripting (XSS) attacks:
http://en.wikipedia.org/wiki/Cross-site_scripting