Finally, we use the gem Sanitize to clean up this XHTML and take out anything that is legal but not necessarily safe.
Are we to assume that the list: a, abbr, acronym, address, [alt], b, big, blockquote, br, caption, center, cite, [class], code, col, colgroup, datetime, dd, del, dfn, div, dl, dt, em, h1, h2, h3, h4, h5, h6, [height], hr, [href], i, img, ins, kbd, li, name, ol, p, pre, q, samp, small, span, [src], strike, strong, sub, sup, table, tbody, td, tfoot, th, thead, [title], tr, tt, u, ul, var, [width] is still up to date? Also, what's the code string to embed video?
Yep, the list of allowed html is still up-to-date, with the exception of the embed code. And the code string to embed video is just whatever those allowed sites offer you as a copy & paste for embed - the exact code is always quite long and complex, so we haven't figured out a succinct way to put it into the allowed list yet.
Comment on Tutorial: HTML Sanitizing and Parsing
samjohnsson Sat 13 Nov 2010 10:31AM UTC
Comment Actions
admin-franny (Guest) Sat 13 Nov 2010 11:30AM UTC
Comment Actions