Skip to content
This repository was archived by the owner on Oct 13, 2021. It is now read-only.

Allow HTML5 in announcements - #549

Merged
germsvel merged 1 commit into
masterfrom
gv-allow-iframe
Sep 28, 2018
Merged

germsvel merged 1 commit into
masterfrom
gv-allow-iframe

Conversation

@germsvel

@germsvel germsvel commented Sep 21, 2018 •

Copy link
Copy Markdown
Contributor

This partially resolves #492

What?

We change HtmlSanitizeEx from basic_html to html5. That function is still a work-in-progress according to some comments in the source code, but I think it is safe enough for us to use since this is an internal tool. See source code at: https://github.com/rrrene/html_sanitize_ex/blob/master/lib/html_sanitize_ex/scrubber/html5.ex

Why?

The main driver behind this is the ability to add <iframe>s so we can add video in an announcement. The html_sanitize_ex library allows us to create a custom sanitizer where we could do basic html + iframes, but I think it makes sense to go with the html5 sanitizer even if it's a work in progress.

At some point, it might be nice to add oembed so that someone can just put a link and we can retrieve it for them, but allowing the rendering of <iframe>s is a pre-requisite for that anyway, so I think this is a good first step for those that want to add video to their announcements.

Screenshots

screen shot 2018-09-21 at 4 49 24 pm

screen shot 2018-09-21 at 4 49 18 pm

What?
======

We change `HtmlSanitizeEx` from `basic_html` to `html5`. That function
is still a work-in-progress according to some comments in the source
code, but I think it is safe enough for us to use since this is an
internal tool. See source code at:
https://github.com/rrrene/html_sanitize_ex/blob/master/lib/html_sanitize_ex/scrubber/html5.ex

Why?
=====

The main driver behind this is the ability to add <iframe>s so we can
add video in an announcement. The `html_sanitize_ex` library allows us
to create a custom sanitizer where we could do basic html + iframes, but
I think it makes sense to go with the html5 sanitizer even if it's a
work in progress.

At some point, it might be nice to add oembed so that someone can just
put a link and we can retrieve it for them, but allowing the rendering
of <iframe>s is a pre-requisite for that anyway, so I think this is a
good first step for those that want to add video to their announcements.
@germsvel
germsvel merged commit 0f2d2d0 into master Sep 28, 2018
@germsvel
germsvel deleted the gv-allow-iframe branch September 28, 2018 15:29

This branch was successfully deployed

1 active deployment
constable-api-staging-pr-549 — dd9ea30e Deployed Sep 21, 2018 by tjmw
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Embed Video

3 participants