Manual talk:$wgRawHtml

Ehmm... who has written this Crap ? There is a Link to $wgGroupPermissions with no Instructions how to do it.

Can somebody please rewrite this Instructions how (?) to enable at locked Sites?


 * You do it exactly the same way, set  to  .  The bit about   is to limit editing of the wiki to known / responsible users.  Otherwise anybody can come along and insert what ever HTML code they like into your pages.  Bit of a security problem that ;-) -- Dr DBW  |  talk  22:45, 26 September 2007 (UTC)

"This is very dangerous"
The warning "This is very dangerous on a publicly editable site" is unspecific. Why is it dangerous? Does it for example enable an exploit that would let someone hack into the MediaWiki site? Or does it merely allow Javascript that would allow a malicious person to harm a user's computer if they run it. -- Cabalamat 20:24, 23 October 2008 (UTC)
 * It allows javascript, which in turn allows people to steal cookies and by that hijack sessions. If you manage to do that with an admins session, you can severely damage the wiki. Allowing users to add JavaScript that is run by other users basically means any user can hijack any other user's account.
 * Full HTML also allows for inclusion of flash or java applets, which may open the wiki for additional attacks. -- Duesentrieb ⇌ 21:36, 23 October 2008 (UTC)
 * I think that the article should tell the reasons why allowing raw HTML is bad. Specifically, it should mention Javascript attacks, XSS, etc. --Lance E Sloan 12:15, 27 October 2008 (UTC)
 * added a link to http://en.wikipedia.org/wiki/Session_hijacking -- Duesentrieb ⇌ 15:08, 27 October 2008 (UTC)


 * Yeah I just stuck Template:XSS alert on here too, which makes things very clear ...and very yellow. Maybe a bit over the top.
 * The XSS FAQ seems like a good explanation of the issues.
 * -- Harry Wood 15:14, 27 October 2008 (UTC)