htmLawed: tweak allowed attributes

This commit is contained in:
Andrew Dolgov 2012-10-30 16:34:17 +04:00
parent 120c2b016f
commit 3795b73034
1 changed files with 1 additions and 1 deletions

View File

@ -2593,7 +2593,7 @@
$res = trim($str); if (!$res) return ''; $res = trim($str); if (!$res) return '';
$config = array('safe' => 1, 'deny_attribute' => 'style', 'comment' => 1, 'cdata' => 1); $config = array('safe' => 1, 'deny_attribute' => 'style, width, height', 'comment' => 1, 'cdata' => 1);
$res = htmLawed($res, $config); $res = htmLawed($res, $config);
if (get_pref($link, "STRIP_IMAGES", $owner)) { if (get_pref($link, "STRIP_IMAGES", $owner)) {