sanitize: allow <xml:namespace> (thanks, livejournal)

This commit is contained in:
Andrew Dolgov 2016-02-05 11:31:13 +03:00
parent 0edf1d0dc0
commit 50bda3fefb

View file

@ -979,7 +979,7 @@
'ol', 'p', 'pre', 'q', 'ruby', 'rp', 'rt', 's', 'samp', 'section',
'small', 'source', 'span', 'strike', 'strong', 'sub', 'summary',
'sup', 'table', 'tbody', 'td', 'tfoot', 'th', 'thead', 'time',
'tr', 'track', 'tt', 'u', 'ul', 'var', 'wbr', 'video' );
'tr', 'track', 'tt', 'u', 'ul', 'var', 'wbr', 'video', 'xml:namespace' );
if ($_SESSION['hasSandbox']) $allowed_elements[] = 'iframe';