Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8224971
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 7, 20262026-06-07T15:15:18+00:00 2026-06-07T15:15:18+00:00

Ideally I want to allow users to edit HTML like tumblr does where you

  • 0

Ideally I want to allow users to edit HTML like tumblr does where you can edit your themes HTML in the browser. You get given also full control.
Ive heard of tools such html-purifier.

Other than ”purifying” the HTML what other steps should br taken.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-07T15:15:21+00:00Added an answer on June 7, 2026 at 3:15 pm

    Some days ago I asked a similar question which might help you.

    I would store all user-generated HTML on another domain/subdomain to avoid cookie stealing and make your cookies HttpOnly, so that they cannot be accessed with JavaScript. You could set your cookies (for authentication etc.) on the main domain only without subdomains. Additionally you could use CSRF tokens to avoid automated abuse.

    If you want to disallow harmful code/JavaScript you have to filter your HTML, if you do so, you should just whitelist all allowed tags, not blacklisting forbidden tags (because new ones have come with HTML5 and there are even browser-specific ones).

    Another challenge is the filtering of attributes (event attributes like onclick allowing to execute JavaScript).

    Another user also called my attention to the Content Security Policy which is a header (but is unfortunately only supported by a few browsers).

    But it depends on how much freedom you want to give to your users.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Pretty self explanatory, I want to allow html from users to be displayed on
Ideally I want a function something like the following (this example doesn't compile): void
I want to create a simple graphical user interface to allow non-technical users to
I'd like to allow users of my web application to upload the contents of
I am new to .NET and ideally want to make several layers of abstraction
I am trying to put the following code into VBA. What I ideally want
I have a situation where ideally I want to be able to log-in to
Whats the best way to zip up files using C#? Ideally I want to
Ideally I just want a list of strings, or Hashmap String,String : List<String> =
I want to make an FTP connection (ideally using Coldfusion 8, but Java is

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.