Using tag 'literal' with class 'html' is not allowed

Author Message

Jeroen Sangers

Tuesday 17 October 2006 8:17:30 am

I have some articles in which I placed some HTML code using the <literal class="html"> element. Now that I review those articles, I see the text "Using tag 'literal' with class 'html' is not allowed." on my page. Has something changed related to the literal tag in the latest relaese?

Xavier Dutoit

Tuesday 17 October 2006 12:06:30 pm

Yes, new setting (security), that's disabled by default now.

You can reactivate it in the ini file.

X+

http://www.sydesy.com

Pascal France

Tuesday 24 October 2006 10:04:16 am

Hi,

I have just upgraded from 3.7.5 to 3.7.9 and now I have too:

Using tag 'literal' with class 'html' is not allowed

instead of the texts (in the front and backend)

What is the ini file Xavier speak about ?

And I don't understand what does mean this message because I use FCKeditor on my site, so I never use HTML code like <literal class="html">

Regards

Pascal

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Kristof Coomans

Tuesday 24 October 2006 11:17:17 am

In content.ini.append.php, add:

[literal]
AvailableClasses[]=html

Here's the security notice in the default content.ini file, so you're warned:

The class 'html' is disabled by default because it gives editors the possibility to insert html and javascript code in XML blocks. Don't enable the 'html' class unless you really trust all users who has privileges to edit objects containing XML blocks.

independent eZ Publish developer and service provider | http://blog.coomanskristof.be | http://ezpedia.org

Pascal France

Tuesday 24 October 2006 11:26:27 am

Hi,

Thanks a lot Kristof.

Nothing to fear, it's my own site and I'm the only redactor ;-)

Regards

Pascal

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Pascal France

Tuesday 24 October 2006 11:38:25 am

Hi,

In ezp 3.8.3 ( ezpublish-3.8.3-gpl.tar.bz2), content.ini contains:

[literal]
AvailableClasses[]=html

but ezp 3.8.4 (ezpublish-3.8.4-gpl.tar.bz2) contains:

[literal]
AvailableClasses[]
# The class 'html' is disabled by default because it gives editors the
# possibility to insert html and javascript code in XML blocks.
# Don't enable the 'html' class unless you really trust all users who has
# privileges to edit objects containing XML blocks.
#AvailableClasses[]=html

It's for this reason I didn't face this problème with my 3.8.3 site.

Regards

Pascal

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Gemma C R

Thursday 06 September 2007 2:41:21 am

We have to upgrade the version of PHP and the ezPublish have to been upgrade too. I upgrade the version 3.6 to 3.7. When I try to enter I have this message :<b>"Using tag 'literal' with class 'html' is not allowed".</b>

What I have to change to the ezPublish go right? I try to make all that I seen on the forums but I doen't have any exit.

Please. Someone knows how to resolve this problem

Thanks

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 19 2025 02:16:25
Script start
Timing: Jan 19 2025 02:16:25
Module start 'layout'
Timing: Jan 19 2025 02:16:25
Module start 'content'
Timing: Jan 19 2025 02:16:26
Module end 'content'
Timing: Jan 19 2025 02:16:26
Script end

Main resources:

Total runtime1.5143 sec
Peak memory usage4,096.0000 KB
Database Queries75

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0074 589.3047152.6406
Module start 'layout' 0.00740.0031 741.945339.4766
Module start 'content' 0.01051.5023 781.4219697.0703
Module end 'content' 1.51280.0014 1,478.492216.1250
Script end 1.5142  1,494.6172 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00370.2413160.0002
Check MTime0.00160.1076160.0001
Mysql Total
Database connection0.00150.102410.0015
Mysqli_queries1.438895.0134750.0192
Looping result0.00080.0514730.0000
Template Total1.479097.720.7395
Template load0.00200.129820.0010
Template processing1.477097.538320.7385
Template load and register function0.00010.007510.0001
states
state_id_array0.00120.081610.0012
state_identifier_array0.00070.043520.0003
Override
Cache load0.00180.1157520.0000
Sytem overhead
Fetch class attribute can translate value0.00160.103350.0003
Fetch class attribute name0.00120.0793100.0001
XML
Image XML parsing0.00190.122350.0004
class_abstraction
Instantiating content class attribute0.00000.0009100.0000
General
dbfile0.00120.0807280.0000
String conversion0.00000.000540.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
3content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
7content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
10content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
1content/datatype/view/ezxmltags/literal.tpl<No override>extension/community/design/standard/templates/content/datatype/view/ezxmltags/literal.tplEdit templateOverride template
2content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 25
 Number of unique templates used: 7

Time used to render debug report: 0.0002 secs