Just have a minute, but it seems we could do this easily enough in a
config file:

MarkUp('pre', 'html', '/<html>(.*?)<\/html>/se',
'BOLTescape(str_replace("&lt;", "<", "$1"))');  // <html>

We could make it more sophisticated, but this ought to work.  Just
tried a simple test, and it looks ok. But you need to really be
careful if you have ANYTHING on a site that is editable--like a
comment box or a sandbox or whatever.  You will open yourself up to
the most wild of attacks. I mean even a title action or a member
registration form.  You have to be VERY careful where and how you
allow access. Put it on a site and I could possibly hack into your
site in 5 minutes.

Of course, you can already put most html tags in BoltWire and they are
recognized. What is the problem with just dumping text in directly
with the html already? The <nolines></nolines> tag is supposed to take
care of the line break problem, though I admit the whole line break
thing needs to be revisited at some point...  Hopefully soon...  We
could work on a better html solution at that time if we wanted... But
limited html is more secure than full html.

Let me know if this doesn't work for you...

Dan



On Fri, Jan 30, 2009 at 4:11 PM, Shawn and Adriela Hoffman
<[email protected]> wrote:
> Having an optional <html></html> markup would be very helpful!  I have
> wished for that so many times!  I agree that it should be disabled by
> default and only enabled by an admin if they so desire.  But I would really
> like that!  I tried to make my own plugin awhile back to do that, but it
> didn't really work (because of my lack of php programming knowledge).
>
> There are many times that I want to take a word document and put it on my
> website, but I don't want to have to go back through the whole document and
> reformat it with Boltwire markup, so I take the HTML and put it in and embed
> page and then put that into my markup.  It would be so much nicer to be able
> to just have a <html></html> markup option.
>
> So that's my vote!  :-)  an HTML markup would be a great option.  And again,
> it should be disabled by default and only enabled by admins who know the
> risks.
> It would only be a security risk if there are multiple people who can edit a
> website, right?  And even then it would only be a risk if one of those
> people wanted to do damage. right?  I am using Boltwire as a CMS and I am
> the only one who can log onto the website.
>
> ~Shawn
>
> >
>

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"BoltWire" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/boltwire?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to