From: Andrew Dolgov Date: Tue, 19 Mar 2013 10:32:26 +0000 (+0400) Subject: strip_harmful_tags: expand the allowed list X-Git-Tag: 1.7.5~111 X-Git-Url: https://git.wh0rd.org/?a=commitdiff_plain;h=10b55a120ce1c937325921b699cd6264d5c35e68;p=tt-rss.git strip_harmful_tags: expand the allowed list --- diff --git a/include/functions.php b/include/functions.php index 50bdc13a..8dba7461 100644 --- a/include/functions.php +++ b/include/functions.php @@ -2624,9 +2624,15 @@ function strip_harmful_tags($doc) { $entries = $doc->getElementsByTagName("*"); - $allowed_elements = array('p', 'br', 'div', 'table', 'tr', 'td', 'th', - 'ul', 'ol', 'li', 'blockquote', 'span', 'html', 'body', 'a', 'img', - 'video', 'audio', 'source', 'object', 'embed'); + $allowed_elements = array('a', 'address', 'audio', + 'b', 'big', 'blockquote', 'body', 'br', 'cite', + 'code', 'dd', 'del', 'details', 'div', 'dl', + 'dt', 'em', 'footer', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', + 'header', 'html', 'i', 'iframe', 'img', 'ins', 'kbd', + 'li', 'nav', 'ol', 'p', 'pre', 'q', 's','small', + 'source', 'span', 'strike', 'strong', 'sub', 'summary', + 'sup', 'table', 'tbody', 'td', 'tfoot', 'th', 'thead', + 'tr', 'track', 'tt', 'u', 'ul', 'var', 'wbr', 'video' ); if ($_SESSION['hasSandbox']) array_push($allowed_elements, 'iframe');