Welcome to the Question2Answer Q&A. There's also a demo if you just want to try it out.

Disable HTML for users

+1 vote
208 views
asked Aug 26, 2015 in Q2A Core by SN
I am using the Markdown editor and it seems that users on my site are able to post HTML in questions, comments, and answers. Is that a normal behavior ? Isn't it dangerous (XSS hacks) ? How can I disable it ?

Thanks
commented Aug 27, 2015 by Jonatan
I suggest you use for questions and answers the "Basic Editor" and Q2A Embed  to videos and images https://github.com/NoahY/q2a-embed
 I think more Friendly and mild.
commented Aug 28, 2015 by SN
@Jonatan this is not a solution, I don't want to use the "Basic Editor", because there are some options (for code etc.) that we need and they are not in the Basic Editor. My question very simple: users on my site are able to post HTML in questions, comments, and answers. Is that a normal behavior ? Or is it dangerous ? I don't know if it is the normal behavior of Q2A or if some plugin have activated this option ..

1 Answer

–1 vote
answered Aug 27, 2015 by aygnbyc
yoursite.com/admin/posting   u can fix
commented Aug 27, 2015 by SN
I don't see on this page an option to disable the usage of HTML for answers/comments/questions. There is just an option that enable/disable a customized HTML message for answers/comments/questions. This is not what I want.
asked Aug 31, 2015 in Q2A Core by SN How to disable posting HTML
...