Please make the customizing forum easier to use

jfriendjfriend Registered Users Posts: 8,097 Major grins
edited January 29, 2009 in Dgrin Forum Support
On behalf of the customizing forum, I'd like to make an appeal to allow the text script and /script tags to be in postings in the customizing forum in their full unmodified splendor.

Someone at Smugmug has configured vBulletin to disallow script tag text in postings because there is a fear that this is somehow a security risk. If people were indeed allowed to post live javascript in the forum, there might be a security risk to that, but this is JUST text. When it gets to a browser, it looks no more like a script than the rest of this posting. Script tags typed into a dgrin posting look only like this to the browser:

<script>

This is text. It's never going to trigger a script. Please, please improve the usability of the customizing forum and turn off the feature that mangles anything we type with script tags in it. This is pure text. It can't be interpreted as a script inside a dgrin posting.

I know I've asked for this before and I was told it was a security risk. I don't understand how it can possibly be a risk and it's a daily annoyance to those who try to support dgrin users with javascripting. If somebody can explain to me how this is actually a security risk, I will stop asking. If nobody can explain how it is actually a security risk (which nobody has to date), then please turn it off in that forum where scripts are exchanged all the time.

On behalf of all the users in the customizing forum, I'm asking for this consideration and change.
--John
HomepagePopular
JFriend's javascript customizationsSecrets for getting fast answers on Dgrin
Always include a link to your site when posting a question

Comments

  • jfriendjfriend Registered Users Posts: 8,097 Major grins
    edited January 29, 2009
    Bump. Any one listening?
    --John
    HomepagePopular
    JFriend's javascript customizationsSecrets for getting fast answers on Dgrin
    Always include a link to your site when posting a question
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited January 29, 2009
    jfriend wrote:
    Bump. Any one listening?
    Hey John, we're always listening - I'm sure you know we've all been swamped with the Bay Photo pro release.

    Hang on let me consult with bigwebguy.

    Please be patient, I'm traveling back east today and won't be able to answer again until Friday, thank you very very very very much!
  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited January 29, 2009
    sorry john. script tags are only parsed when the forum is set to not allow html. if the forum is set to allow html, script tags are executed.

    we have some forums where html is allowed and unfortunately there is no way to individually block script tags from only those forums. we have to do it at the global level. I dunno if this has changed with more recent versions of vBulletin, but its the way it is right now.
    Pedal faster
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited January 29, 2009
    bigwebguy wrote:
    I dunno if this has changed with more recent versions of vBulletin, but its the way it is right now.
    We'll be upgrading soon, we've a server install happening within days I hope, that will beef up the server for Dgrin and Advrider. Then, we can upgrade Dgrin's version of Vbulletin. We'll see what the latest version allows.

    Thanks.
Sign In or Register to comment.