Closed (outdated)
Project:
Drupal core
Version:
7.x-dev
Component:
filter.module
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
29 May 2010 at 08:55 UTC
Updated:
29 Nov 2010 at 04:04 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
greenreaperSame here, but I'm also seeing this in Drupal 6.19. Subscribing.
Comment #2
taslett commentedIn D7 the function drupal_strip_dangerous_protocols http://api.drupal.org/api/function/drupal_strip_dangerous_protocols/7
contains a list of allowed protocols.
There is a variable filter_allowed_protocols which it attempts to read from although I can't see where it is actually set.
I'm not sure if the clsid is considered dangerous, if it should be added to the list or added via a config settings page somewhere if needed.
Comment #3
anrikun commentedFYI, the CKEditor SWF module provides a workaround to this issue.
Comment #4
sunNo harm in adding that, I think.
Comment #5
sun#4: drupal.filter-clsid.4.patch queued for re-testing.
Comment #7
sun#4: drupal.filter-clsid.4.patch queued for re-testing.
Comment #9
sun#4: drupal.filter-clsid.4.patch queued for re-testing.