First time here? Check out the FAQ!
2

Strip out HTML tags from user profiles
 

Hi - is there any way to strip out all HTML from the user profile fields? If a user updates their profile I would prefer it to strip out all HTML which is currently does not seem to be doing, I can even enter HTML tags on "real name" field, which render on the user profile page post update.

http://i.imgur.com/ldaFTQV.png (Example that renders)

To enter a block of code:

  • enter empty line after your previous text
  • paste or type the code
  • select the code and press the button above
Preview: (hide)
whackhat's avatar
1
whackhat
asked 11 years ago

Comments

That's a good catch. This would be a nice feature. It can be added as a enable/disable option in conf file. So that if admin wants to disable it he can, and switch back if he changes his mind.

Chankey Pathak's avatar Chankey Pathak (11 years ago)

I think of another feature where you can "nofollow" all external links, it will save from spam and link-juice.

Chankey Pathak's avatar Chankey Pathak (11 years ago)
see more comments

1 Answer

0

Added strip tags to the "real name" field, thanks.

On the profile html is sanitized, so no urgent changes are necessary there.

To enter a block of code:

  • enter empty line after your previous text
  • paste or type the code
  • select the code and press the button above
Preview: (hide)
Evgeny's avatar
13.2k
Evgeny
answered 11 years ago
link

Comments

see more comments