Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

If you set "editor.contentFilter.allowIFrameallowIframe" value to false, insertion of <iframe> tag by the user is restricted and the tag is automatically removed.

Code Block
languagejs
themeEmacs
titlesynapeditor.config.js
{
	'editor.contentFilter.allowIframe': false
}


Status
colourYellow
titleRELEASE 2.7.0 OR ABOVE
 If you set "editor.contentFilter.allowEmbed" value to false, insertion of <embed> tag by the user is restricted and the tag is automatically removed.

Code Block
languagejs
themeEmacs
titlesynapeditor.config.js
{
	'editor.contentFilter.allowIFrameallowEmbed': false
}

...


Status
colourYellow
titleRELEASE 2.7.0 OR ABOVE
 If you set "editor.contentFilter.allowIScriptallowObject" value to false, insertion of <script> <object> tag by the user is restricted and the tag is automatically removed.

Code Block
languagejs
themeEmacs
titlesynapeditor.config.js
{
	'editor.contentFilter.allowScriptallowObject': false
}

RELEASE 2.3.0 OR ABOVE

Status
colourYellow
titleRELEASE 2.7.0 OR ABOVE
 If you set 'editor.contentFilter.allowScriptallowLink' value to falseinsertion of <a> <link> tag by the user is restricted and the tag is automatically removed.

Code Block
languagejs
themeEmacs
titlesynapeditor.config.js
{
	'editor.contentFilter.allowLink': false
}







...

HTML SCRIPT & EVENT ATTRIBUTES

Warning
title주의!

You cannot be held responsible for security issues arising from the use of the option.


If you set "editor.contentFilter.allowIScript" value to false, insertion of <script> tag by the user is restricted and the tag is automatically removed.

Code Block
languagejs
themeEmacs
titlesynapeditor.config.js
{
	'editor.contentFilter.allowScript': false
}


Status
colourYellow
titleRELEASE 2.7.0 OR ABOVE
 If you set 'editor.contentFilter.allowEventAttribute' value to true, you can use event attributes (onclick, onload, onchange, ....) in HTML tags.

...