Communities

Writing
Writing
Codidact Meta
Codidact Meta
The Great Outdoors
The Great Outdoors
Photography & Video
Photography & Video
Scientific Speculation
Scientific Speculation
Cooking
Cooking
Electrical Engineering
Electrical Engineering
Judaism
Judaism
Languages & Linguistics
Languages & Linguistics
Software Development
Software Development
Mathematics
Mathematics
Christianity
Christianity
Code Golf
Code Golf
Music
Music
Physics
Physics
Linux Systems
Linux Systems
Power Users
Power Users
Tabletop RPGs
Tabletop RPGs
Community Proposals
Community Proposals
tag:snake search within a tag
answers:0 unanswered questions
user:xxxx search by author id
score:0.5 posts with 0.5+ score
"snake oil" exact phrase
votes:4 posts with 4+ votes
created:<1w created < 1 week ago
post_type:xxxx type of post
Search help
Notifications
Mark all as read See all your notifications »
Q&A

Welcome to Codidact Meta!

Codidact Meta is the meta-discussion site for the Codidact community network and the Codidact software. Whether you have bug reports or feature requests, support questions or rule discussions that touch the whole network – this is the site for you.

Comments on What html tags can we use in posts?

Parent

What html tags can we use in posts?

+11
−0

So, I finally got around to looking at the second Review Panel draft, and was surprised by the ability to make collapsible sections in posts. From the comments, I wasn't the only one.

Whoa, whoa, whoa, slow down, you can make collapsable sections? Tell me that if posts support any form of HTML coding, that at least CSS and JS are screened so that users can't just arbitrarily execute code on the browser page. — DonielF

@DonielF Yes via <details> for everything and within that <summary> for the title. And no, not everything goes. There is a whitelist. :D — luap42

This is really just me satisfying my own curiosity, but what specifically is allowed on the site? I mean, obviously not script tags or any other security breaking tags, but what about other feature tags like <details>?

History
Why does this post require attention from curators or moderators?
You might want to add some details to your flag.
Why should this post be closed?

1 comment thread

General comments (1 comment)
Post
+12
−0

For obvious reasons, we do not allow you to use any tag or attribute you want. All tags, that aren't on a special inclusion list are stripped from the input.

There are two lists, one for posts and one for comments.

Posts (Question, Answer, Article, IIRC user profiles; so generally everything longer) can contain as tags:

  • a
  • p
  • span
  • b
  • i
  • em
  • s
  • strong
  • hr
  • h1, h2, h3, h4, h5, h6
  • blockquote
  • img
  • strike
  • del, ins
  • code
  • pre
  • br
  • ul, ol, li
  • sup, sub
  • section
  • details, summary
  • table, thead, tbody, tr, th, td

These tags can furthermore use the following attributes:

  • id
  • class
  • href
  • title
  • src
  • height
  • width
  • alt
  • dir
  • lang
  • start
  • rowspan
  • colspan

Comments (and possibly some other shorter text types) may contain:

  • a
  • b
  • i
  • em
  • strong
  • strike
  • del
  • code

These tags can use the attributes

  • href
  • title

This is the current list of available tags. It might, though, change in the future. For example <details> and <summary> were only added recently.

The source code with the most recent list can be found here for:

History
Why does this post require attention from curators or moderators?
You might want to add some details to your flag.

1 comment thread

General comments (6 comments)
General comments
Moshi‭ wrote about 4 years ago

Thanks, this is exactly what I wanted

Dani‭ wrote about 4 years ago

Also the <span> and <style>.

luap42‭ wrote about 4 years ago

@Dani shouldn't be supported. Take a look at my user profile. I added a <span> around "deploys" and added a <style> tag that should give every element an outline. Both are scrubbed from the HTML, as you can see from the html inspector / the no effect.

Dani‭ wrote about 4 years ago

@luap42 When asking a question, the preview shows the styled text (but I didn't post with any with it, so I don't know if it goes away).

Skipping 1 deleted comment.

deleted user wrote over 3 years ago

I think you forgot to use <img> tag

luap42‭ wrote over 3 years ago

@Istiakshovon the IMG tag is already in the list between BLOCKQUOTE and STRIKE.