Editor & BB Code Manager

Editor & BB Code Manager 2.0.1 Patch Level 1

No permission to download
Hi katsulynx (@Lukas W. ) I would like to point out something I think should be taken into consideration.

Altough using the HIDE bbcode doesn't display the content on the thread until you like/reply (depending on the settings you specify), there's a hole in this script. If people use the search, they can search for hidden content as well.

Example:

let's say I put a password into the hide bbcode. I'd do this way:

[hide] a1s2d3f4g5 [/hide]

Now, if a user, by search (doing Search by Thread selecting a single thread or even by using the generic forum search) goes looking for "a1s" (trying to guess the password) the search will display the thread if the result matches, then, he might keep trying adding another letter, let's say: "a1sx".

No results because it doesn't match, but this also means he can still try again and again until he guesses the final hidden text: a1s2d3f4g5 .

This shouldn't be a problem for most people (including me), but if the hidden content can only be unlocked by upgraded accounts (paid), smart people might use this exploit to find hidden content, so I was thinking about making it possible to strip the content of [hide] bbcodes from the searches, too, if possible.

I hope it helps.
 
How come this doesn't cover the default list icon? Which contains the indent and lists. It covers the insert dropdown, just not the list dropdown.
 
Hello,
Any way to translate the front editor terms ?
Look at the kl_em_editor_phrases template. All phrases that have a translation are listed there. If any are missing, let me know. Translation for them works fine on all my installations.

How come this doesn't cover the default list icon? Which contains the indent and lists. It covers the insert dropdown, just not the list dropdown.
Alignment is not a dropdown but an own function set, that has an active state, etc. Can't just treat it like a dropdown, even if it looks like one.

Should have that sorted for the next update.

There's not much to do about it. As long as it doesn't actually break anything, that's just what happens when stuff's being converted to HTML and back.

Not sure if there's a whole lot I can or should do here. XF by default pushes all BB codes as plain text into the search index without any pre-processing. IMO, they should strip out all tags at the very least, but without any pre-processing in place, I got no place to hook into to make this work for all places simultaneously. I've reported it to Chris & co for now.

Please consider import from TH DataTables.
I don't have any plans to add something like that. Such conversions are best done manually, as I can't cover all potential places that might use BB codes, such as content types that have been added by 3rd party add-ons.
 
Top Bottom