Disallow classes in user-submitted content

This commit is contained in:
Kijin Sung 2016-12-08 17:45:03 +09:00
parent 5e5c2d918a
commit e9bfb0e298
2 changed files with 4 additions and 3 deletions

View file

@ -104,6 +104,7 @@ class HTMLFilter
$config = \HTMLPurifier_Config::createDefault();
// Customize the default configuration.
$config->set('Attr.AllowedClasses', array());
$config->set('Attr.AllowedFrameTargets', array('_blank'));
$config->set('Attr.DefaultImageAlt', '');
$config->set('Attr.EnableID', true);