Inserting an IFRAME or PHP script into a profile

16 years 11 months ago #38632 by Strappy Music
Is there any way at all I can set up my cb system so that users can insert IFRAMES or PHP scripts into their profile? I've made an editor field but the editor strips any code it doesn't like.

I'm using TMEdit, so I had a look at the javascript and found the filter, and removed the iframe element from the filter. This worked so much as when going from HTML view back to WYSIWYG view the iframe is shown, however when I save it seems that either community builder or joomla are having a crack at the code as well because when I view the profile, or go back in to edit again, the code has been stripped :(

This is sending me nuts, does anybody have a solution?

Please Log in to join the conversation.

16 years 11 months ago #38637 by mikko
Allowing this would create huge security problems. How would you validate against malicious php scipts, iframe content which would contain malware or cross site scripting?

In general, it is only a good thing that this is not allowed.

Mikko

Please Log in to join the conversation.

16 years 11 months ago #38650 by Strappy Music
Replied by Strappy Music on topic Re:Inserting an IFRAME or PHP script into a profil
Thank you for the feedback.

Security issues aside, is it actually possible?

Please Log in to join the conversation.

16 years 11 months ago #38652 by mikko
As I said in another thread, this would be quite trivial to implement as a plugin, but due to the security issues it is not likely that anyone will just publish this kind of plugin anytime soon.

So the verdict for this is: Not possible without coding.

Mikko

Please Log in to join the conversation.

16 years 11 months ago #38663 by Strappy Music
Replied by Strappy Music on topic Re:Inserting an IFRAME or PHP script into a profil
Hi thanks for your reply.

I had to get my fingers dirty for this one and have a play around with the "hello world" plugin to get it working. I thought that was out of my league but I seemed to have hacked-and-pasted a version that does the job quite nicely. So now I have the best of both worlds: an Iframe which I can insert into certain users profiles, and no chance for users to go inserting their own iframes into their profiles :)

cheers!

Please Log in to join the conversation.

16 years 7 months ago #46054 by victune
Strappy Music wrote:

Hi thanks for your reply.

I had to get my fingers dirty for this one and have a play around with the "hello world" plugin to get it working. I thought that was out of my league but I seemed to have hacked-and-pasted a version that does the job quite nicely. So now I have the best of both worlds: an Iframe which I can insert into certain users profiles, and no chance for users to go inserting their own iframes into their profiles :)

cheers!


Hello Strappy Music,

Can you please share with us your solution here or here:
www.joomlapolis.com/index.php?option=com_joomlaboard&Itemid=38&func=view&catid=13&id=46051#46051

Regards.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.226 seconds

Facebook Twitter LinkedIn