Print Page | Close Window

HTML in post

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=22170
Printed Date: 08 April 2026 at 11:56am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: HTML in post
Posted By: suedechaser
Subject: HTML in post
Date Posted: 11 December 2006 at 5:43am
Hello everyone,

Is it possible to somehow copy/paste html into a post - like a newsletter template - so it can be viewed like an emailed newsletter?

regards

suede



Replies:
Posted By: iSec
Date Posted: 11 December 2006 at 6:57am

You could enable the ALLOW HTML feature from the admin area but i don't recommend it due to obvious security issues...  Can't you just copy the actual content (not the html code) of that page ... and paste it right away onto the RTE?



Posted By: es0p0s
Date Posted: 11 December 2006 at 11:23am
where is the ALLOW HTML feature to enable it ,don't worry about security issues it's my prob.
also a copy /paste of the html code will have the results of view as the page was posted on itself ?


Posted By: suedechaser
Date Posted: 11 December 2006 at 1:11pm
Hi Info Tech,

If I understand you correctly, you say to copy the actual newsletter page into the forum - ie right click, select all, copy, paste - seems to work OK.

But isn't this copying the html code too? What about the security risk?

regards

suede


Posted By: iSec
Date Posted: 11 December 2006 at 6:41pm
es0p0s, I just checked teh admin area and found out that this feature is no longer available. I'm sure it was removed to reduce security risks, still there is always way to mod it if you know how to.
 
Suedechaser, yes, it is copying the HTML code too, but there is no security risk in that as you have already seen its output. If you allow HTML on your forum then someone might come in and post something malicious (which you do not have control over) that can cause problems.


Posted By: suedechaser
Date Posted: 12 December 2006 at 1:32am
Hi Info Tech,

Thanks for clarifying that. But how do I know that code I paste in, using this method, isn't already malicious? I don't have a really tight grasp on html, so please excuse if this is a simple question.

regards

suede


Posted By: iSec
Date Posted: 12 December 2006 at 4:08am
Well, if you look at the content which you would like to post, how does it behave? There is no risk if it is behaving normally like a regular web page. WWF also filters the content of the posted message to make sure it does not change the layout of the forum tables.
 
For the HTML, I remember a few years back I used to post at a php-based message baord made by infopop, I could post a code that messes up the entire site page. So having it enabled was a bad idea. Hopefully one day it will be so that admins can specifiy which group is permitted to use it rather than having it available to all.
 
But what are you trying to do exactly? Can you give more details or an example on how you want to do it?


Posted By: es0p0s
Date Posted: 12 December 2006 at 9:20am
well there is no risk the site is on a vpn with 7 subnets and about 200 users I know them personally  :) I'll  look  for the mod you said


Posted By: Mikey
Date Posted: 12 December 2006 at 1:55pm
The RTE auto filters out anything malicious

-------------
Handyman man?


Posted By: iSec
Date Posted: 12 December 2006 at 2:50pm
Got it guys,
I just didn't remember exactly where the option is for it. Here is how to enable HTML on your forum:
 
1- Open the forum directory
2- Open the file: RTE_configuration/RTE_setup.asp
3- Look for the code on line 107

Const blnHTMLView = false 'Allows the user to view the HTML code, you may need to dsiable this for extra security

4- Change the value in red from false to true
 
And to post using HTML, there will be an icon shown in the RTE box as shown below:
Click on that icon, type or your HTML code again and then re-click the icon to see the output.


Posted By: suedechaser
Date Posted: 13 December 2006 at 5:19am
Hi Info Tech,

What I'm wishing to do is simply copy / paste a few newsletters that I receive via email, into the forum as a normal post.

I followed your suggestions from earlier and it seems to work OK. I was just wondering if any newsletter that I paste in could, in some way, have malicious code in that I don't know about.

If the Const blnHTMLView was set to true and I could use the method as you have suggested above, and Mikey is also correct that the RTE filters out bad stuff - I should be OK. What do you think?

regards

suede



Posted By: iSec
Date Posted: 13 December 2006 at 6:08am
Yes but it isn't required. I'd just copy/paste without enabling the HTML.



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net