Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - WYSIWYG HTML Editor
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

WYSIWYG HTML Editor

 Post Reply Post Reply
Author
Vaseline View Drop Down
Groupie
Groupie


Joined: 03 May 2003
Status: Offline
Points: 66
Post Options Post Options   Thanks (0) Thanks(0)   Quote Vaseline Quote  Post ReplyReply Direct Link To This Post Topic: WYSIWYG HTML Editor
    Posted: 11 May 2003 at 9:55pm

I have turned off the WYSIWYG HTML Editor thing, but dont see a big difference. How can one turn of the possibility to change font, size, colour, including pictures and all that jive? Or even better choose what abilities should be a part of editor and what not?



Edited by Vaseline
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 12 May 2003 at 4:04am

Both editors allow the use of changing fonts, colours etc. the only way around this is to edit the files directly and remove these parts.

The files are:-

IE_message_form_inc.asp
message_form_inc.asp

Back to Top
headshot_001 View Drop Down
Newbie
Newbie


Joined: 20 May 2003
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote headshot_001 Quote  Post ReplyReply Direct Link To This Post Posted: 20 May 2003 at 9:03pm
I have been lead to believe that if you have this type
of function, it allows a user to submit *malicious*
code. If this is the case, is it possible to turn it off by
doing what you have mentioned in tis previous post?
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 21 May 2003 at 1:48am

You can turn off the WYSIWYG Editor in the admin area.

There are filters in place that filter out malicious code from posts.

Back to Top
headshot_001 View Drop Down
Newbie
Newbie


Joined: 20 May 2003
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote headshot_001 Quote  Post ReplyReply Direct Link To This Post Posted: 21 May 2003 at 2:18am
Is this the section you are referring to?

<snip>
WYSIWYG HTML Editor for Windows IE 5+
This is the type of editor you use to post messages if
you are a Windows IE5+ user. If you turn this function
off everyone will use the Basic message editor.
If you want greater security turn this feature off, but
you will lose functionality.
</snip>

If so, then I have it already switchd to *off* - and it is
still appearing?!

When you say there is filters, what do they do? Do
they strip out particular tags etc?
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 21 May 2003 at 2:36am

If you turn off the WYSIWYG editor you have a basic editor instead, the basic editor uses forum codes eg. [B][/B] for bold.

This means that the user input is strickly controlled as HTML can not be placed directly in posts and forum codes need to be used instead to format text.

The filters strip malicious codeusing filters that removes or encodes anything that could be used for malicious code, eg. JavaScript, VbScript, certain HTML and CSS tags, etc. are all removed from the post. This prevents malicious code such as cross site scripting, SQL injections, etc. being placed into posts.

Back to Top
hans3702 View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 23 March 2003
Location: Netherlands
Status: Offline
Points: 141
Post Options Post Options   Thanks (0) Thanks(0)   Quote hans3702 Quote  Post ReplyReply Direct Link To This Post Posted: 21 May 2003 at 4:22am

Hi BoRg, can you or some else give me a hint how to dasable the filter for posing made bij the administator?

I think is just one call to a function someware but I haven;t found it jet.

Back to Top
robert2504 View Drop Down
Newbie
Newbie


Joined: 08 March 2002
Location: United States
Status: Offline
Points: 29
Post Options Post Options   Thanks (0) Thanks(0)   Quote robert2504 Quote  Post ReplyReply Direct Link To This Post Posted: 21 May 2003 at 2:27pm
Is it possible to allow the Administrator to post HTML Code and not allow the rest of the users?
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.