|
Joined: Jun 2006
Posts: 987 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 987 Likes: 24 |
What about
HTML is disabled. UBBCode is enabled.
What happen if I turn on html? advantages and disadvantages?
|
|
|
|
Joined: Dec 2003
Posts: 6,560 Likes: 78
|
Joined: Dec 2003
Posts: 6,560 Likes: 78 |
I would not enable html for everyone. If they post incorrect html code it can break the page/post. Also it allows the bad creative people another avenue to exploit.
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Jun 2006
Posts: 16,292 Likes: 116
|
Joined: Jun 2006
Posts: 16,292 Likes: 116 |
Security is the disadvantage... IMHO "html" posting shouldn't ever be enabled; if they know enough to post proper html then they should know enough to do annoying things like embed javascript in postings or post un-nested html.
|
|
|
|
Joined: Jun 2006
Posts: 987 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 987 Likes: 24 |
Gizmo.. has anything changed regarding enable HTML? I was asked by a member.
Is it the same risk as in 2013?
|
|
|
|
Joined: Jun 2006
Posts: 16,292 Likes: 116
|
Joined: Jun 2006
Posts: 16,292 Likes: 116 |
It'll always be the same, as one can use their own tags... I'd rather craft a million allowed custom bbcodes than ever enable HTML for guests/users.
|
|
|
|
Joined: Dec 2003
Posts: 6,560 Likes: 78
|
Joined: Dec 2003
Posts: 6,560 Likes: 78 |
+1
Even the admin can break the site with improperly formatted HTML tags. Let alone any security risks
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Jun 2006
Posts: 987 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 987 Likes: 24 |
Thanks for answers, i figured it but needed to ask in order to be safe
|
|
|
|
Joined: Jun 2006
Posts: 16,292 Likes: 116
|
Joined: Jun 2006
Posts: 16,292 Likes: 116 |
Just as a simple example of what looks like simple code; as an admin go ahead and post a HTML post just including the following: Notice that by having a stray close table or div tag how your entire forum is messed up on any page displaying this post (the thread, portal news, active topics in this case); this can happen with HTML posts... This is just a minor display problem (and these are two common tags for HTML), not even touching on potential security issues. I would be surprised to hear a legitimate excuse on why a normal user would need HTML posting access on your forum that can't be solved with UBBCode; all of the formatting coding they should need is represented by UBBCode, HTML/Web Design tools aren't generally something one would need to contribute to a conversation.
|
|
|
0 members (),
744
guests, and
147
robots. |
Key:
Admin,
Global Mod,
Mod
|
|
|
|