Commit Graph

27 Commits

Author SHA1 Message Date
alecpl
1d3596dd61 - Don't allow short form of empty <strong> tag 2010-08-03 11:48:24 +00:00
alecpl
be6f3a9d28 - Improve parsing of styled empty tags in HTML messages (#1486812) 2010-06-23 06:57:45 +00:00
alecpl
a0d29e518f - Fix RFC2397 handling in wash_style() 2010-06-07 06:47:14 +00:00
alecpl
b6f04054d1 - support base URL for inline images 2010-05-27 13:34:58 +00:00
alecpl
0b7f3a8ab2 - Add support for data URI scheme [RFC2397] (#1486740) 2010-05-22 07:27:15 +00:00
alecpl
9ef5fa51fb - fix <span>0</span> (#1486645) 2010-04-21 13:56:53 +00:00
alecpl
a72ad65724 - Fix invalid font tags which cause HTML message rendering problems (#1486521) 2010-02-28 08:07:45 +00:00
alecpl
7435e3bc32 - fix empty A tag handling (#1486272) 2009-11-03 17:41:54 +00:00
svncommit
e98f249172 Added # to washtml's regex for safe links (some list digests have tables of contents that use internal links). 2009-08-19 18:33:26 +00:00
svncommit
5f8d31f9be better solution for HTML washing encoding issue 2009-07-31 02:58:31 +00:00
svncommit
659672ebf9 fix washing of HTML encoded in something other than UTF-8 2009-07-30 04:07:26 +00:00
alecpl
2337a82f72 - Fix displaying of HTML messages with unknown/malformed tags (#1486003)
- Some other changes for styled HTML display
2009-07-28 08:41:50 +00:00
alecpl
503e019a56 - Fix HTML messages output with empty block elements (#1485974) 2009-07-17 07:32:59 +00:00
alecpl
f7fff8f682 - Allow WBR tag in HTML message (#1485960) 2009-07-03 18:36:09 +00:00
thomascube
4cc74f7269 Treat 'background' attributes the same way as 'src' (another XSS vulnerability) 2009-01-20 16:28:33 +00:00
alecpl
7f62581c10 - Smart Tags and NOBR tag support in html messages (#1485363, #1485327) 2008-09-17 07:47:32 +00:00
thomascube
a47acc56c6 Allow content of HTML head sections to be processes 2008-09-16 13:06:20 +00:00
thomascube
c505e59a6d Respect Content-Location headers in multipart/related messages (#1484946) 2008-09-05 09:29:06 +00:00
thomascube
d368a68ed7 Reverted r1607. See #1485137 for explanations 2008-07-22 17:13:47 +00:00
alecpl
4897adcbd4 #1485137: added 'form' to allowed elements list 2008-07-22 10:38:43 +00:00
thomascube
21e724153e Improve HTML sanitization with washtml 2008-07-22 08:01:42 +00:00
alecpl
18ebb902d5 #1485097: Re-enable background attribute in HTML messages 2008-06-15 11:23:18 +00:00
thomascube
350459486d Change meta-charset specififcation in HTML to UTF-8; no need for mb_convert_encoding() anymore 2008-06-07 12:51:21 +00:00
thomascube
a8755664af Allow <body> tag in HTML messages which will be converted to <div class='rcmBody'> 2008-06-04 09:40:17 +00:00
thomascube
65cc1c196f Chech for mb_convert_encoding first because mbstring is optional for RoundCube + add some phpdoc 2008-06-04 09:13:06 +00:00
alecpl
68217c548a -add convert encoding before html parsing 2008-06-03 17:07:53 +00:00
thomascube
45f56c1c40 Replace our crappy html sanitization with the dom-based washtml script + fix inline message parts + remove old code + add some doc comments 2008-05-29 16:10:42 +00:00