Okay... So what happened?
#1
Posted 10 May 2012 - 03:15 PM
#2
Posted 10 May 2012 - 03:22 PM
#3
Posted 10 May 2012 - 03:54 PM
#4
Posted 10 May 2012 - 07:55 PM
#5
Posted 10 May 2012 - 08:24 PM
Surely it was just a simple case of raising the issue with Invision and letting their team investigate & patch?
#6
Posted 10 May 2012 - 09:07 PM
#7
Posted 10 May 2012 - 09:39 PM
testing
testingWhy can users still post / use HTML code?
Most BB boards block it outright - to stop any SQL injection.
end test
#8
Posted 10 May 2012 - 09:55 PM
My life has been lost with out this site!! I was so Bored
You must lead a lonely one then!
#9
Posted 10 May 2012 - 10:15 PM
It wasn't users being able to post using html that was the problem. The software checks for malicious code in posts, IPB had already thought of that.Why can users still post / use HTML code?
#10
Posted 10 May 2012 - 10:33 PM
#11
Posted 10 May 2012 - 11:19 PM
It wasn't users being able to post using html that was the problem. The software checks for malicious code in posts, IPB had already thought of that.
Strange that, as that's the whole idea of BB forum, where HTML is substituted for BB code that's specific to the software vendor. A legend if you like, where certain approved tags correspond with certain internal responses. It means that the affect a user has upon the forum is limited to the contents if a posting, it's divorced from the code upon which the whole forum has been created…it's almost a firewall between the user and the back end. As for the idea that IPB has this covered, well, the software vendor recommends that you disable it.
SourceIPS highly recommends you do not enable HTML posting in your community as it is a large security risk. By default, IPS software ships with HTML posting disabled.
#12
Posted 10 May 2012 - 11:22 PM
Also, I can see that "Facebook" is viewing this thread.
#13
Posted 10 May 2012 - 11:23 PM
Law Grad, I can only post what I was told. If you already knew the answer 1) why bother asking, and 2) why not pose the question to NSI in the correct thread?Strange that, as that's the whole idea of BB forum, where HTML is substituted for BB code that's specific to the software vendor. A legend if you like, where certain approved tags correspond with certain internal responses. It means that the affect a user has upon the forum is limited to the contents if a posting, it's divorced from the code upon which the whole forum has been created…it's almost a firewall between the user and the back end. As for the idea that IPB has this covered, well, the software vendor recommends that you disable it.Source
#14
Posted 10 May 2012 - 11:38 PM
Law Grad, I can only post what I was told. If you already knew the answer 1) why bother asking, and 2) why not pose the question to NSI in the correct thread?
I did, when it was last posted / last thread about it, that's now lost from the restore. I'm not having a go Damsel, but I have never seen any forum that allows HTML tags to be used by its members…its kind of the purpose of the BB tags having [ brackets as opposed to < as its an internal code that has no universal effect…just the comments box.I was trying to use brevity, and yes for me that's odd :D in the hope that if the forum goes down again, someone might say "someone did mention an anomaly about HTML" As an aside, it's probably why there have been issues in regards editing posts for formatting / broken links / images not displaying correctly etc.Because, and even allowing for any WYSIWYG text editor that pastes unnecessary code…preview and edit suddenly renders a post full of low level HTML code that can get muddled up. And I repeat again, this isn't a hobby horse or argument, but an attempt at flagging up a genuine concern…so please don't allow it to be ignored based upon "it should be posted there" as it sort of misses the issue. All the best, and a round of applause to all those behind the scenes…including yourself for manning twitter Damsel. :P
#15
Posted 10 May 2012 - 11:56 PM
#16
Posted 11 May 2012 - 05:51 AM
#17
Posted 11 May 2012 - 07:08 AM
#18
Posted 11 May 2012 - 08:50 AM
There are valid reasons to ban / allow HTML - especially given the propensity for people in the News section to copy & paste without using the preview button and generate monstrosities.
#19
Posted 12 May 2012 - 10:32 AM
0 user(s) are browsing this forum
0 members, 0 guests, 0 anonymous users























