Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeArchived Discus...Archived Discus...Developing Under Previous Versions of .NETDeveloping Under Previous Versions of .NETASP.Net 2.0ASP.Net 2.0Portal Security - NoScriptingPortal Security - NoScripting
Previous
 
Next
New Post
12/30/2007 10:47 AM
 

I see where using FilterFlag.NoScripting says it removes "suspect html" from your string - such as:

string input = "<a href='mailto:email@email.com'><b>Send Email</b></a>"
securtiy.InputFilter(input, PortalSecurity.FilterFlag.NoScripting);

But in my DB I still have the bold or anchor (email) tags in place.  Using NoMarkup simply coverts the brackets (<) to &lt; and such.  I do want to strip all html from the input I am receiving. 

Am I missing the obvious?  Or is there a meaning behind the "suspect html" that I've yet to learn about? (Conspiracy?)

Thanks



Andrew Walker

Learn to make your own beer and wine at homeIf you enjoy making your own beer and/or wine - be sure to check out http://www.ForemostBrewing.com
 
New Post
12/30/2007 2:03 PM
 

InputFilter has a number of levels - if you use NoMarkup it simply htmlencodes the content, which is why you're seeing the angle brackets and other characters encoded. This means that the html is effectively converted to plain text- when it's displayed in a browser it will not be interpreted as tags. If you use NoScripting it searchs for potential dangerous strings to remove, this allows developers the option to allow their users to use HTML but protect against common xss/html injection attacks. Where possible you should always use NoMarkup, unless you absolutely need your users to have the capability to use html.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeArchived Discus...Archived Discus...Developing Under Previous Versions of .NETDeveloping Under Previous Versions of .NETASP.Net 2.0ASP.Net 2.0Portal Security - NoScriptingPortal Security - NoScripting


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out