MTCleanHTMLPlugin - borrowing a page from LJ, literally.
Tonight, I borrowed LiveJournal's comment filtering code and made it into a MovableType plugin: MTCleanHTMLPlugin
After all that ramble about having open system and not having been the victim of an exploit, SamRuby inadvertently revealed one gapingly wide hole for me. Not that he did anything to exploit it - I just realized that a bug he tripped over could be used for more nefarious purposes. So, I closed the hole, and after a bit of quick research went a bit further and made a new MovableType plugin. Borrowing LiveJournal's code yields a filter which strips out most nasty ?JavaScript exploits, and attempts to close tags left lazily open.
Hope someone finds a use for it.
Archived Comments