HTML in module headers #7474
Replies: 4 comments
|
Ah, I didn't look closely enough at your example. HTML is allowed, even without enabling the toggle, but only a limited subset of HTML that is deemed to be safe. The filter is intended to disallow dangerous input, which is not restricted to JavaScript, but also includes the However, this behavior was relaxed in DNN 10.3.3 to only target JavaScript and not styles, so the above example should work on a 10.3.3 site (but not on 10.3.2). But, upon testing, it doesn't. My guess is that our filtering approach doesn't work on unclosed HTML (where the header opens a tag and the footer closes the tag). So, for now, adjusting the toggle in Site Settings is going to be the only way to support that approach. Also, note that these settings to restrict JS are enabled in new sites, but disabled for upgrades. |
|
Thanks for the information. |
|
@bdukes @datafastlr in this case we might need a bug report for this discussion. |

Uh oh!
There was an error while loading. Please reload this page.
I guess this one passed me by, but are we no longer able to place HTML in the header and footer of a module (DNN 10.03.03)? (See image).

All reactions