forked from extern/egroupware
8f797be836
- can be used via html class like: $clean_html = html::purify($html); - using it now in eTemplate to remove malicious code from html: a) when displaying "formatted text" b) when "formatted text" get's input by the user
15 lines
490 B
Plaintext
Executable File
15 lines
490 B
Plaintext
Executable File
HTML.MaxImgLength
|
|
TYPE: int/null
|
|
DEFAULT: 1200
|
|
VERSION: 3.1.1
|
|
--DESCRIPTION--
|
|
<p>
|
|
This directive controls the maximum number of pixels in the width and
|
|
height attributes in <code>img</code> tags. This is
|
|
in place to prevent imagecrash attacks, disable with null at your own risk.
|
|
This directive is similar to %CSS.MaxImgLength, and both should be
|
|
concurrently edited, although there are
|
|
subtle differences in the input format (the HTML max is an integer).
|
|
</p>
|
|
--# vim: et sw=4 sts=4
|