Version: 1.00, by Neo
Developer Last Online: Dec 2009
Version: 2.2.x
Rating:
Released: 03-18-2002
Last Update: Never
Installs: 2
No support by the author.
Ok this is a big hack people... and I am sure you want to know what it does.. Ok this is very simple to use. It gives the user the ability to make his own custom style/color for the site, which the user can use, edit, let other users usem and delete. It is all very staright forward to use. This will not impact the sites original sytels or such. Now I have input that users can only edit their own styles, as people with think there are security holes, but I have patched then up, so if they they to mess with the system they will get a error message (Tested) This system I larger and
if you find any errors please report them to me at once.
Updated! 1.3
1) In the admin cp user styles / replacements now have their own section as not to confuse admin in the site styles / replacements.
2) In user options they now have the site styles, and then teh drop down for user styles
3) Security updated.
Add Style:
Modify Style:
Edit Style:
Remove Style:
Customize Style:
Security Preview:
Enjoy. :smoke:
Show Your Support
This modification may not be copied, reproduced or published elsewhere without author's permission.
Disclaimer: Nothing against you, seems like you've done a good job here.
But, I would definitely not let my users mess with styles other people can use. The reason is very simple. Anyone with a little knowledge in Javascript can easily steal cookie data from you with malicious code. So one can create his own style, put some JS code in the header template and bam - anyone using the style (even for once) will have his account stolen.
Originally posted by FireFly Disclaimer: Nothing against you, seems like you've done a good job here.
But, I would definitely not let my users mess with styles other people can use. The reason is very simple. Anyone with a little knowledge in Javascript can easily steal cookie data from you with malicious code. So one can create his own style, put some JS code in the header template and bam - anyone using the style (even for once) will have his account stolen.
True. But this is an addon, while there may be a way to steal cookie data with malicious code. This could be a very usefull hack. I have added some security to the script, but I am still not totally sure about the security like you have said. So firefly do you think there are any steps to take to get around this?
Add a regex that will remove all Javascripts from the templates. It's not the best way to go on this, and while it might make some people angry I think it's worth it.
I would limit it to color changes... the hack I mean. Giving them just the ability to change like.. the text, background, post color, post color #2, and a few other colors.
Edit, just another questioN~what is to stop users to say, making the header look like http://www.thisisanastyilligalsite.com and, you don't notice it, a member chooses this style, notices, and notifies the authorities :x
Just seems like alot of unwanted work/attention....
I think users must NOT have possibilities to change templates.
Only colors and they cannnot share them with others. Nobody want to choose a set from 1000 styles... Just my opinion...
does user edit templates?
if user can edit header, he can add some javascript, as firefly said, and i don't want to have some problems with my users accounts!
How about make an option in the admin, with check boxes to which style fields you allow the users to be able to customize, e.g.
CHECKBOX-Ticked Background Colour
CHECKBOX-Unticked Text Colour etc etc.
And perhaps allow the admin to disable/enable the option for the user to share his/her custom style to others, otherwise the board may end up with 1000 style for people to choose from as someone as mentioned above.
I would defintly go with the color/text size, let them know what it is like to run a forum, most people haveno idea, and I have had requests for them to be able to do that so that would killer to do that.