[wpmu-trac] Re: [WordPress MU Trac] #357: kses.php stripping out all class and id markup from posts

WordPress MU Trac wpmu-trac at lists.automattic.com
Wed Jun 20 12:42:17 GMT 2007


#357: kses.php stripping out all class and id markup from posts
------------------------+---------------------------------------------------
 Reporter:  conoro      |        Owner:  donncha 
     Type:  defect      |       Status:  assigned
 Priority:  high        |    Milestone:  WPMU 1.0
Component:  component1  |      Version:  1.0     
 Severity:  major       |   Resolution:          
 Keywords:              |  
------------------------+---------------------------------------------------
Changes (by donncha):

  * owner:  somebody => donncha
  * status:  new => assigned

Comment:

 Have you tried writing a post as a non-administrator in WP? Does the same
 thing happen? The kses.php shipped with WPMU is largely the same as WP's,
 except with some extra warning messages.

 There's a very good chance that you're writing in WP as a user with
 unfiltered_html capability. That doesn't exist in WPMU because it would be
 a security risk.

-- 
Ticket URL: <http://trac.mu.wordpress.org/ticket/357#comment:1>
WordPress MU Trac <http://mu.wordpress.org/>
WordPress Multiuser


More information about the wpmu-trac mailing list