-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
questionFurther information is requestedFurther information is requested
Milestone
Description
Consider validating HTML prior to saving and stripping out scripts to improve security.
But...is this really necessary? If these pages are all being published to the author's website, isn't security their problem?
Maybe we can have an "advanced" configuration option that disables script removal if the user has selected this. Or maybe we skip this feature and let the user do what they want. I'm a little torn on this one.
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requested