mirror of
https://github.com/ezyang/htmlpurifier.git
synced 2024-11-10 15:48:42 +00:00
84aa2ca390
- Fix (or null) bug in configdoc git-svn-id: http://htmlpurifier.org/svnroot/htmlpurifier/trunk@1695 48356398-32a2-884e-a903-53898d9a118a
21 lines
829 B
Plaintext
21 lines
829 B
Plaintext
HTML.ForbiddenAttributes
|
|
TYPE: lookup
|
|
VERSION: 3.1.0
|
|
DEFAULT: array()
|
|
--DESCRIPTION--
|
|
<p>
|
|
While this directive is similar to %HTML.AllowedAttributes, for
|
|
forwards-compatibility with XML, this attribute has a different syntax. Instead of
|
|
<code>tag.attr</code>, use <code>tag@attr</code>. To disallow <code>href</code>
|
|
attributes in <code>a</code> tags, set this directive to
|
|
<code>a@href</code>. You can also disallow an attribute globally with
|
|
<code>attr</code> or <code>*@attr</code> (either syntax is fine; the latter
|
|
is provided for consistency with %HTML.AllowedAttributes).
|
|
</p>
|
|
<p>
|
|
<strong>Warning:</strong> This directive complements %HTML.ForbiddenElements,
|
|
accordingly, check
|
|
out that directive for a discussion of why you
|
|
should think twice before using this directive.
|
|
</p>
|