Code review comment for lp:~tblue/quam-plures/bug13_fix_credits_disp

Revision history for this message
Tilman Blumenbach (tblue) wrote :

The reason I chose 'htmlbody' for the output filter is that we use it in other places where we output plugin descriptions etc. as well, so I thought it was appropriate. Admittedly, it allows all HTML and only makes sure things like the charset are correct.

Of course it would be better to restrict the HTML tags that can be used -- not only on the credits page but in the admin interface as well. 'entityencoded' should work, let me check. I will change the code to use that filter if everything works.

« Back to merge proposal