Feature request: Option to trust list owners' HTML

Bug #786932 reported by Cedders
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
GNU Mailman
New
Undecided
Unassigned

Bug Description

List owners may want to edit the list information or subscribe pages to link to CSS or JS on a main site, to use a standard style or do form validation, for example. The checks against cross-site scripting prevent this, and the text suggesting shell access may be inappropriate. The site admin may trust the list owners, but it may not be desirable for privacy or firewall reasons to give them SSH access to the Mailman server. (previously suggested on bug 266273)

It would therefore be very useful to have a global option to turn off the XSS checking as needed. A simple patch is attached to provide this option. I didn't find existing translations for the relevant error messages (in French or Spanish at least).

Revision history for this message
Cedders (cedric-gn) wrote :
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.