Skip to content
This repository has been archived by the owner on Nov 9, 2017. It is now read-only.

Should escape message by default (via HTML::chars) #9

Open
jeremeamia opened this issue Jul 26, 2010 · 1 comment
Open

Should escape message by default (via HTML::chars) #9

jeremeamia opened this issue Jul 26, 2010 · 1 comment
Labels

Comments

@jeremeamia
Copy link
Contributor

Secure by default. Prevents XSS. Make a way to send raw if needed.

@bobeagan
Copy link
Contributor

What about making a config option of whitelisted tags? I've regularly used messages that have bold, italic, underline or links in them.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants