HTML whitelisting / template security
Tobias Prinz <[email protected]>
| Newsgroups | gmane.comp.web.freemarker.user |
|---|---|
| Message-ID | <[email protected]> |
Hey there, is there any way to disable certain elements that someone might use in a template before rendering? Some kind of html black/whitelisting? Filtering out Javascript? I just realized that it might not be smart to allow different users to do uncontrolled templating on the same domain, because they might hijack domains and all those nice things. Sorry for writing in a hurry, for some reasons I always seem to get those ugly ideas ten minutes before a security-related meeting ;-) Bye, Tobias ------------------------------------------------------------------------------ This SF.net Dev2Dev email is sponsored by: Show off your parallel programming skills. Enter the Intel(R) Threading Challenge 2010. http://p.sf.net/sfu/intel-thread-sfd