Closed (won't fix)
Project:
CKEditor 4 - WYSIWYG HTML editor
Version:
7.x-1.2
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
22 May 2013 at 12:33 UTC
Updated:
8 Aug 2013 at 12:33 UTC
Jump to comment: Most recent file
Comments
Comment #1
Andrei.Sapeshko commentedРossible solution.
Comment #1.0
Andrei.Sapeshko commentedSome additions
Comment #2
drifter commentedI think the point they made is that the content is loaded as HTML rather than plain text in CKEditor, and so the XSS attacks could fire while editing content. Nevertheless, this should at least be a clearly labeled option that I can disable, as currently it is erasing important parts of the content's HTML!
Comment #3
jcisio commentedThere won't be that option. From the CKEditor CTO: http://stackoverflow.com/a/12099443/417401.
So the AJAX XSS filter was added to protect from server side. If it has bug, then let's fix it instead of removing the filter.
Comment #3.0
jcisio commentedSome additions