Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-347 Browsing Issues
  3. GTWY-352

Allow Formatting of User Conent?

XMLWordPrintable

    • Icon: Work Task Work Task
    • Resolution: Won't Do
    • Icon: Major Major
    • Recycle Bin
    • None
    • User Interface
    • None

      Some of the Descriptions for Datasets have html formatting (Bold, Italics, etc...).

      What is our policy on allowing User content to have formatting?

      If we allow formatting we should be dilligent about what type of formatting we allow. If we aren't a user can (untentinall or intenionally) ruin our page formatting by using some <div> blocks.

      We could open our Users to Cross-Site Scripting (XSS) attacks:
      http://en.wikipedia.org/wiki/Cross-site_scripting

              Unassigned Unassigned
              nhook Nathan Hook
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: