MyShaarli/application
ArthurHoaro 9ff17ae20e Add markdown_escape setting
This setting allows to escape HTML in markdown rendering or not.
The goal behind it is to avoid XSS issue in shared instances.

More info:

  * the setting is set to true by default
  * it is set to false for anyone who already have the plugin enabled
  (avoid breaking existing entries)
  * improve the HTML sanitization when the setting is set to false - but don't consider it XSS proof
  * mention the setting in the plugin README
2017-03-04 09:38:12 +01:00
..
config Minor code cleanup: PHPDoc, spelling, unused variables, etc. 2016-10-20 11:36:11 +02:00
.htaccess .htaccess files: support Apache 2.4+ syntax 2016-11-08 11:38:14 +01:00
ApplicationUtils.php Minor code cleanup: PHPDoc, spelling, unused variables, etc. 2016-10-20 11:36:11 +02:00
Cache.php Cache: simplify cached content cleanup, improve tests 2015-08-13 23:51:31 +02:00
CachedPage.php Minor code cleanup: PHPDoc, spelling, unused variables, etc. 2016-10-20 11:36:11 +02:00
FeedBuilder.php Add a persistent 'shorturl' key to all links 2016-12-12 03:03:12 +01:00
FileUtils.php Replace $GLOBALS configuration with the configuration manager in the whole code base 2016-06-11 09:30:56 +02:00
HttpUtils.php Merge pull request #623 from ArthurHoaro/security/reverse-proxy-ban 2016-10-12 14:48:57 +02:00
Languages.php Initialize a translation function 2016-08-07 11:54:39 +02:00
LinkDB.php Add a persistent 'shorturl' key to all links 2016-12-12 03:03:12 +01:00
LinkFilter.php Add a persistent 'shorturl' key to all links 2016-12-12 03:03:12 +01:00
LinkUtils.php Add a persistent 'shorturl' key to all links 2016-12-12 03:03:12 +01:00
NetscapeBookmarkUtils.php Add a persistent 'shorturl' key to all links 2016-12-12 03:03:12 +01:00
PageBuilder.php New init function for plugins, supports errors reporting 2016-10-14 13:22:58 +02:00
PluginManager.php New init function for plugins, supports errors reporting 2016-10-14 13:22:58 +02:00
Router.php Fix: add missing final newlines, untabify text 2016-08-13 14:22:22 +02:00
TimeZone.php Minor code cleanup: PHPDoc, spelling, unused variables, etc. 2016-10-20 11:36:11 +02:00
Updater.php Add markdown_escape setting 2017-03-04 09:38:12 +01:00
Url.php Minor code cleanup: PHPDoc, spelling, unused variables, etc. 2016-10-20 11:36:11 +02:00
Utils.php Add a persistent 'shorturl' key to all links 2016-12-12 03:03:12 +01:00