dtcd27183 2017-07-28 14:39
浏览 68
已采纳

安全进入但正确显示ckeditor

I'd like to use Ckeditor for an internal messaging system on a website.

I'd like that users can format text but I'm aware of vulnerabilities, is there any way to make a compromise ?

I've heard of a BBcode plugin, or ways to sanitize data entered from another topic (CKEditor security best practices), how would it work ?

  • 写回答

1条回答 默认 最新

  • dongli9894 2017-07-31 09:14
    关注

    If you want to clean your code just in CKEditor (in client side ) check

    http://docs.ckeditor.com/#!/guide/dev_advanced_content_filter

    PS. but i suggest to perform clean in backend too.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 如何在node.js中或者java中给wav格式的音频编码成sil格式呢
  • ¥15 不小心不正规的开发公司导致不给我们y码,
  • ¥15 我的代码无法在vc++中运行呀,错误很多
  • ¥50 求一个win系统下运行的可自动抓取arm64架构deb安装包和其依赖包的软件。
  • ¥60 fail to initialize keyboard hotkeys through kernel.0000000000
  • ¥30 ppOCRLabel导出识别结果失败
  • ¥15 Centos7 / PETGEM
  • ¥15 csmar数据进行spss描述性统计分析
  • ¥15 各位请问平行检验趋势图这样要怎么调整?说标准差差异太大了
  • ¥15 delphi webbrowser组件网页下拉菜单自动选择问题