Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 292900

FilterHtml data loss when iframe and/or textarea is allowed

$
0
0

Problem/Motivation

Since #2441811 landed, it seems that any text format that allows <iframe> or <textarea> within the html filter can lead to data loss.

Steps to reproduce

Configure a text format to allow:
<em> <strong> <cite> <blockquote cite> <code> <li> <dl> <dt> <dd> <h4 id class> <h5 id class> <br> <img src alt width height class> <table class> <caption class> <tbody> <thead> <tfoot> <th> <td> <tr> <iframe title src> <div class> <p class> <h2 id class> <h3 id class> <span id class> <a rel accesskey target title name id href hreflang class data-cta-track-sync data-cta-track-async data-cta-description data-cta-placement> <ul type class> <ol start type class> <hr>

Add some content with an <a> tag.

Notice that the <a> will not be rendered on the front-end, and is not persisted into the database.

I'm filing this as critical because existing content being re-saved can lead to data loss.

Proposed resolution

TBD

Remaining tasks

TBD

User interface changes

TBD

API changes

TBD

Data model changes

TBD

Release notes snippet

TBD


Viewing all articles
Browse latest Browse all 292900

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>