Re: Secure data coming from a WYSIWYG editor

2013-06-27 Thread Simone Camillo Buzzi
Thank for your help, it's was I was searching for Kind regards Simone Buzzi 2013/6/26 Maurizio Cucchiara > Out of there, there are a lot of WYSWYG editors (like CKEditor) which allow > to define the list of the supported tags. > > For what concerns the server side aspect, I'd suggest you JSOUP

Re: Secure data coming from a WYSIWYG editor

2013-06-26 Thread Maurizio Cucchiara
Out of there, there are a lot of WYSWYG editors (like CKEditor) which allow to define the list of the supported tags. For what concerns the server side aspect, I'd suggest you JSOUP. It allows to clean the HTML submitted by the user [1]. Also, have a look at hdiv [2], IIRC there is a plugin for s

Secure data coming from a WYSIWYG editor

2013-06-26 Thread Simone Camillo Buzzi
Hi, how can I secure data coming from a WYSIWYG editor? I want to allow user to change properties of the text but not to link images or add scripts to his post. I'll use this feature to allow user to add comment or compile complex pages. I'm not worried about data coming from the edito