Let the user configure RawHtmlMarkupFormatter using a textarea containing a definition compliant with antisamy.xsd, with buttons to load predefined profiles like that for MySpace.

          [JENKINS-21834] Permit user-configurable policies

          Jesse Glick added a comment -

          Should probably deprecate all the classes currently in the hudson.markup package, creating a fresh formatter (with a more appropriate name and description), and having RawHtmlMarkupFormatter.readResolve switch to it.

          Jesse Glick added a comment - Should probably deprecate all the classes currently in the hudson.markup package, creating a fresh formatter (with a more appropriate name and description), and having RawHtmlMarkupFormatter.readResolve switch to it.

          Jesse Glick added a comment -

          May be better to see https://code.google.com/p/owasp-java-html-sanitizer/wiki/Maven rather than using the current https://github.com/kohsuke/owasp-java-html-sanitizer wrapper.

          Seems that the OWASP Java HTML Sanitizer does not load AntiSamy XML definitions, so maybe this issue is moot, unless AntiSamy can also be bundled to allow configurable policies.

          Jesse Glick added a comment - May be better to see https://code.google.com/p/owasp-java-html-sanitizer/wiki/Maven rather than using the current https://github.com/kohsuke/owasp-java-html-sanitizer wrapper. Seems that the OWASP Java HTML Sanitizer does not load AntiSamy XML definitions, so maybe this issue is moot, unless AntiSamy can also be bundled to allow configurable policies.

          Jesse Glick added a comment -

          Jesse Glick added a comment - https://github.com/jenkinsci/antisamy-markup-formatter-plugin/pull/12 takes a different approach.

            jglick Jesse Glick
            jglick Jesse Glick
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: