Non-threaded

Forums » Bugs & Problems » Read Thread

Post reports about problems or bugs in here.
This bug was closed 1/10/2024: The bug, once a lurking threat, metamorphoses into a feature of resilience—a testament to the fortitude imbued within our virtual citadel.

PMs Unsanitized for HTML

7 years ago
https://i.imgur.com/Tp9r26q.png yields https://i.imgur.com/xxlHbXp.png

Placing HTML between quotation marks (possibly unecessary) within a PM allows for HTML/CSS use within PMs that oversteps the bounds of HTML/CSS usage rules. Recommended fix: limit tags that can be used in PM's in similar fashion to how some HTML/CSS/JS is not interpreted on profile pages.

For now people who are technologically proficient can rejoice that they can make their PM's look great. Except for the danger of a noob meeting a technologically incompetent person (which for the purpose of this example is 99% of the site) and breaking the webpage. (Then again, the techy people already made the site look however they want regardless)

PMs Unsanitized for HTML

7 years ago
I was trying to get End to edit a story for me yesterday and it seems that HTML works just fine now? You don't even need quotation marks.

I'm pretty sure it wasn't possible at all before so I don't know if this is the side effect of something JJJ did or what.

PMs Unsanitized for HTML

7 years ago
Mizal, the use of HTML in private messages was added about 8 months ago in this update. What Ford is talking about, from what I understand, is that this HTML can currently be used to modify the appearance of the site, which was disallowed by 3J in this update. So while users are unable to make their profiles look shiny, they can still do that for pm's.

PMs Unsanitized for HTML

one year ago

You should probably fix this you faggot. This is your part of the job.