vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   signitures by user (https://vborg.vbsupport.ru/showthread.php?t=50924)

Mickie D 03-28-2003 07:22 PM

signitures by user
 
right i have moved my board with no hassle to a secure server :) WOO HOO

but alot of my members have html and pics in the signitures :(

i am happy for them to have these signitures but i told them they will have to send me the pics and i will upload them to our server :)

but now the only problem is how do i enable html in signitures by user ????

filburt1 03-28-2003 07:34 PM

Don't do it. By enabling HTML you open up every XSS vulnerability in vB.

Mickie D 03-28-2003 08:56 PM

ok then how about vb pics code in sigs can i enable that to run ????? one member at a time :)

my members like the signitures and the ones with the html i allow i trust ... my board is a nice place we are friendly :)

Mickie D 03-29-2003 11:41 AM

anyone know if what i want to do is possable ???

just want to be able to set html or vbcodes in signitures by user :) instead of a one set global option !

thanks in advnace

Mickie D

Mickie D 03-30-2003 10:45 AM

*BUMP

Dean C 03-30-2003 04:42 PM

why not just explain to them how to use the [img] tags and then make a tag for tables and such - good subsitute for html as you can limit the parameters - that's what i love about vbcodes :)

- miSt

Mickie D 04-02-2003 10:28 AM

that is a very good idea... but i have 6000 members already some using vbcode in there sig ... and why i turned it off was because if you read an old post then the members would see the "this site has secure and non secure items" etc.... so if the members wanted to have a picture in there signiture which is 100% fine by me they can give me the image i upload it to a members_pics folder and they can call it fom ther with there html :)

Link14716 04-02-2003 10:48 AM

If it has HTML, don't you think they can very easily just change it to point to their image somewhere else? Your better off turning off HTML and the [img] tag and creating a bbcode that calls the image, but points specifically to the member_pics folder.

Or am I missing something?

Mickie D 04-05-2003 08:56 PM

no m8 that is sound advice :) ... i just wanted to allow it user by user.

when i turn on vb img code the members that already have pictures in vb img code messes the site security up :(

thanks everyone for the replys i would really like to be able to click a button to allow html for certain members and i understand it would be a big hack ... so thanks for the advice :)


All times are GMT. The time now is 06:59 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01105 seconds
  • Memory Usage 1,720KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (9)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete