Secure html
No security coverage
Though allowing editors to embed arbitrary content on the website is generally a bad idea, sometimes it is a clear business requirement.
This module allows you to limit potential damage from embedded html content and lower down security risks.
It adds "secure html" filter that wraps everything in an iframe, which can be configured as a "sandbox" to prevent executing scripts or accessing parent window (see https://www.w3schools.com/tags/att_iframe_sandbox.asp).
There are 2 ways of using this module
- Use it as a text format filter (but keep in mind that this filter is irreversible and must be the last in the sequence)
- Use it from your module via theme callback
$dangerous_html = [ '#theme' => 'secure_html', '#content' => '<html...', '#attributes' => [ 'sandbox' => 'allow-forms allow-scripts', ], ];
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.
Activity
Releases
| Version | Type | Core | Release date | |
|---|---|---|---|---|
| 1.0.x-dev | Dev | May 8, 2023 |