Topic on Skin talk:Citizen

Summary by Alistair3149

Patch merged into master

2603:8001:6603:9871:480F:1EE9:474C:9DA2 (talkcontribs)

It seems like the Citizen skin enables raw HTML embedding, and "$wgRawHtml = false;" does nothing to disable it, which seems unsafe. Am I missing something during setup to make this more secure?

Octfx (talkcontribs)

That does indeed happen when collapsible sections are created. In the meantime you can disable those by setting $wgCitizenEnableCollapsibleSections to false.

Octfx (talkcontribs)
Alistair3149 (talkcontribs)

Merged into master, should be fixed now.