time-exchange-gr / oscurrency

Open Source Time Exchange derived from Insoshi
http://time-exchange.gr
Other
9 stars 0 forks source link

sanitize user html #92

Open 3point2 opened 12 years ago

3point2 commented 12 years ago

it seems like users have access to a lot of html tags. i added an iframe to the blog and it worked. not sure if user submitted stuff is filtered or not, but i need to test. also see #91