Maybe just as a side note to that. 

Reason why STK escapes all html by default is to make it less likely that 
anyones templates will be vulnerable to XSS, so every time you need to call 
decode() you should think twice (in this case decoding input from FCK is ok) 
about whether you need it and how you will make sure no one (incl. editor) can 
insert some malicious scripts.


BTW the "old way" was:

${stk.decode(content).text!}

what you describe as "old way" is what you use in any template that is not 
using STK renderer but plain Freemarker renderer.

HTH,
Jan


On May 15, 2012, at 7:53 PM, Jean-Francois Nadeau (via Magnolia Forums) wrote:

> The old way
> ${content.text!}
> 
> The new '4.5' way 
> [#if content.text?has_content]
>   ${cmsfn.decode(content).text}
> [/#if]
> 
> -- 
> Context is everything: 
> http://forum.magnolia-cms.com/forum/thread.html?threadId=a30a568e-158f-4d29-b3e2-361f09aa424e
> 
> 
> ----------------------------------------------------------------
> For list details, see http://www.magnolia-cms.com/community/mailing-lists.html
> Alternatively, use our forums: http://forum.magnolia-cms.com/
> To unsubscribe, E-mail to: <[email protected]>
> ----------------------------------------------------------------




----------------------------------------------------------------
For list details, see http://www.magnolia-cms.com/community/mailing-lists.html
Alternatively, use our forums: http://forum.magnolia-cms.com/
To unsubscribe, E-mail to: <[email protected]>
----------------------------------------------------------------

Reply via email to