[Mailman-Users] Archived html messages

Mark Sapiro msapiro at value.net
Tue Jan 9 00:07:50 CET 2007


Jay Rogers wrote:
>
>How does one change/configure Mailman to get these
>archived HTML attachments to display as expected?


Set

ARCHIVE_HTML_SANITIZER = 3

in mm_cfg.py, but first read the comments about this setting in
Defaults.py, and perhaps also google 'xss' and read some of the
relevant hits.

Basically, doing this allows anyone who can post to a list to place
malicious HTML on your web site.

-- 
Mark Sapiro <msapiro at value.net>       The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan



More information about the Mailman-Users mailing list