We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

XSS filtering recommendation?

How Do I?

mavrekh's avatar
mavrekh
1 posts
10 years ago
mavrekh's avatar mavrekh

Dear EE forum,

What is the latest EE recommendation on activating XSS filtering in the control panel?

The security guidelines (https://ellislab.com/expressionengine/user-guide/development/guidelines/security.html) seem to imply that it should be ON. I did notice that turning it on in the config file converts any HTML comments in channel entries into visible gibberish when entries are updated. Is there any way to avoid this, for example by turning off filtering for entry updates, or by excluding HTML comments from a list of specialcharred tags somewhere?

On the other hand, this post: https://mithra62.com/blog/view/why-you-should-care-about-securitee says that “ExpressionEngine recommends disabling XSS filtering though YOU SHOULDN’T”, although I haven’t been able to find anything to that effect on EE sites.

What is the “official” EE stance on XSS filtering?

Misha

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.