mirror of
https://github.com/ezyang/htmlpurifier.git
synced 2024-11-10 07:38:41 +00:00
d3c04de9dc
git-svn-id: http://htmlpurifier.org/svnroot/htmlpurifier/trunk@1575 48356398-32a2-884e-a903-53898d9a118a
13 lines
539 B
Plaintext
13 lines
539 B
Plaintext
URI.DisableExternalResources
|
|
TYPE: bool
|
|
VERSION: 1.3.0
|
|
DEFAULT: false
|
|
--DESCRIPTION--
|
|
Disables the embedding of external resources, preventing users from
|
|
embedding things like images from other hosts. This prevents access
|
|
tracking (good for email viewers), bandwidth leeching, cross-site request
|
|
forging, goatse.cx posting, and other nasties, but also results in a loss
|
|
of end-user functionality (they can't directly post a pic they posted from
|
|
Flickr anymore). Use it if you don't have a robust user-content moderation
|
|
team.
|