mirror of
https://github.com/ezyang/htmlpurifier.git
synced 2024-11-14 01:08:41 +00:00
12b811d749
Signed-off-by: Edward Z. Yang <edwardzyang@thewritingpot.com>
17 lines
645 B
Plaintext
17 lines
645 B
Plaintext
Attr.EnableID
|
|
TYPE: bool
|
|
DEFAULT: false
|
|
VERSION: 1.2.0
|
|
--DESCRIPTION--
|
|
Allows the ID attribute in HTML. This is disabled by default due to the
|
|
fact that without proper configuration user input can easily break the
|
|
validation of a webpage by specifying an ID that is already on the
|
|
surrounding HTML. If you don't mind throwing caution to the wind, enable
|
|
this directive, but I strongly recommend you also consider blacklisting IDs
|
|
you use (%Attr.IDBlacklist) or prefixing all user supplied IDs
|
|
(%Attr.IDPrefix). When set to true HTML Purifier reverts to the behavior of
|
|
pre-1.2.0 versions.
|
|
--ALIASES--
|
|
HTML.EnableAttrID
|
|
--# vim: et sw=4 sts=4
|