Filter code trong Drupal từ Stripping Out Code

Filter code trong Drupal từ Stripping Out Code

Code can be dangerous. The right code in the right place brings your site to life, but there are many places where it can be a huge security risk.

Inside your content, code can be dangerous. If you allow people to use PHP, Javascript, iframes or other code inside content, you greatly increase the chances of a malicious script being used.

To minimize this risk, by default Drupal restricts the code you can use in content.

The downside to this is that some common code isn't allowed. For example, most HTML is blocked by default. Here's how to allow those on your site by stopping Joomla from stripping out code.

Text Formats

tutuploadsmedia_1322079982179.png

By default, Drupal content is entered as "Filtered HTML". What does that mean? Drupal explains in the image above.

  • Web page addresses and e-mail addresses turn into links automatically.
  • There are only twelve allowed HTML tags.

Click on the dropdown link and you'll get extra options:

tutuploadsmedia_1322080284110.png

Full HTML is described in this way:

  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.

Plain text is described in this way:

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.

You can also to the Modules page and enable PHP filter:

tutuploadsmedia_1322080495187.png

This is described more simply:

  • You may post PHP code. You should include tags.

How does this impact your content?

tutuploadsmedia_1322080687743.png

Let's see an example of how text filters impact your content. In this example we're adding a Google Map to our content.

If we save this page with Filtered HTML, the end result will look like the image below.

tutuploadsmedia_1322080731057.png

If we save this page with Full HTML, the end result will look like the image below.

tutuploadsmedia_1322080824150.png

Modifying the Text Filters

If the default settings aren't right for you, go to Configuration > Text format.

Filter code trong Drupal từ Stripping Out Code

You'll see that different filters are set up for different user groups. For security reasons, anonymous users and authenticated users only get access to Filtered HTML.

tutuploadsmedia_1322080958715.png

Click on Configure next to any text filter to change the options:

tutuploadsmedia_1322081085284.png

Bạn thấy bài viết này như thế nào?: 
No votes yet
Ảnh của Khanh Hoang

Khanh Hoang - Kenn

Kenn is a user experience designer and front end developer who enjoys creating beautiful and usable web and mobile experiences.

Tìm kiếm bất động sản

 

Advertisement

 

jobsora

Dich vu khu trung tphcm

Dich vu diet chuot tphcm

Dich vu diet con trung

Quảng Cáo Bài Viết

 
7 hướng dẫn IBM giúp tổ chức và doanh nghiệp đối phó với thảm họa

7 hướng dẫn IBM giúp tổ chức và doanh nghiệp đối phó với thảm họa

Chuẩn bị môi trường công nghệ thông tin (CNTT) sẵn sàng với những thảm họa tự nhiên và nhiều nguy cơ khác có thể xảy đến.

Khái niệm mới Decoupling Drupal (decoupled CMS)

Khái niệm mới Decoupling Drupal (decoupled CMS)

Drupal 8 will make huge strides in this area, but alas it's not out yet. Fortunately the answer to the second problem is the first; it is entirely possible to build a solid, scalable, performant RESTful web service with Drupal 7

HTC Salsa: A Review

HTC Salsa: A Review

The name salsa sounds fun, warm an inviting, and yes, it is true of the HTC Salsa. The first thing that caught my eye was the build quality.

Công ty diệt chuột T&C

 

Diet con trung