This repository was archived by the owner on Oct 13, 2021. It is now read-only.
Repository navigation
Allow HTML5 in announcements - #549
Merged
Merged
Conversation
What? ====== We change `HtmlSanitizeEx` from `basic_html` to `html5`. That function is still a work-in-progress according to some comments in the source code, but I think it is safe enough for us to use since this is an internal tool. See source code at: https://github.com/rrrene/html_sanitize_ex/blob/master/lib/html_sanitize_ex/scrubber/html5.ex Why? ===== The main driver behind this is the ability to add <iframe>s so we can add video in an announcement. The `html_sanitize_ex` library allows us to create a custom sanitizer where we could do basic html + iframes, but I think it makes sense to go with the html5 sanitizer even if it's a work in progress. At some point, it might be nice to add oembed so that someone can just put a link and we can retrieve it for them, but allowing the rendering of <iframe>s is a pre-requisite for that anyway, so I think this is a good first step for those that want to add video to their announcements.
MattMSumner
approved these changes
Sep 21, 2018
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This partially resolves #492
What?
We change
HtmlSanitizeExfrombasic_htmltohtml5. That function is still a work-in-progress according to some comments in the source code, but I think it is safe enough for us to use since this is an internal tool. See source code at: https://github.com/rrrene/html_sanitize_ex/blob/master/lib/html_sanitize_ex/scrubber/html5.exWhy?
The main driver behind this is the ability to add <iframe>s so we can add video in an announcement. The
html_sanitize_exlibrary allows us to create a custom sanitizer where we could do basic html + iframes, but I think it makes sense to go with the html5 sanitizer even if it's a work in progress.At some point, it might be nice to add oembed so that someone can just put a link and we can retrieve it for them, but allowing the rendering of <iframe>s is a pre-requisite for that anyway, so I think this is a good first step for those that want to add video to their announcements.
Screenshots