[Owasp-antisamy] antisamy-slashdot-1.2.xml

Arshan Dabirsiaghi arshan.dabirsiaghi at aspectsecurity.com
Sat Aug 16 20:03:42 EDT 2008


Serge,
 
Thanks, we'll clear up the inconsistent comments.
 
Arshan

________________________________

From: owasp-antisamy-bounces at lists.owasp.org on behalf of Serge Droganov
Sent: Sat 8/16/2008 3:14 PM
To: owasp-antisamy at lists.owasp.org
Subject: [Owasp-antisamy] antisamy-slashdot-1.2.xml



Hello,
antisamy-slashdot-1.2.xml misses these tags: <strong> <dl> <dt> <dd>

They are announced at the top of the policy file and missed in it's 
body.

I also think that it's wold be a good idea to create slashdot analogue 
that is compatible to simple version of tiny_mce or may be other 
simple editors.

It's of course not a big deal to create custom policy files but the 
problem is to sync them in future. The user may miss something and it 
would be a potential security hole.

Thank you,
Serge
_______________________________________________
Owasp-antisamy mailing list
Owasp-antisamy at lists.owasp.org
https://lists.owasp.org/mailman/listinfo/owasp-antisamy


-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://lists.owasp.org/pipermail/owasp-antisamy/attachments/20080816/aceb0ebc/attachment.html 


More information about the Owasp-antisamy mailing list