wpmu adaptations
hi there.
I have been thinking about using atahualpa on my wpmu installation but before this I would like to know how extensively your changes for wpmu have been, I mean it would be critically if a little loophole escaped your attention. There is one thing, that I would like to disable: in the backend Atahualpa theme options => HTML/CSS Inserts - this is dangerous, it seems users can insert javascript. How can I quickly disable this section for my wpmu install? Besides, in almost any wpmu installation inserting frames, embeds, javascript, php is disabled and forbidden as its a huge security whole giving random users access to these things. I would very much like to get feedback from the author to see if this theme is really ready for wpmu. |
Quote:
HTML Code:
<li><a href="#" rel="html-inserts">HTML/CSS Inserts</a></li> HTML Code:
<!--<li><a href="#" rel="html-inserts">HTML/CSS Inserts</a></li>--> |
Thx :-) I had half-way foudn that out by myself, was not sure if I missed anything.
besides, is there any other potentially dangerous code in there for a wpmu isntallation where registrations are open for anyone? btw. where can users of wpmu upload their header images? I can't fidn that function. OR do you have to attach the image headers you want to use to a post or just upload into the media manager? |
The upload is different for WPMU users, they'll have to upload through the regular WP editor /media manager and Atahualpa will scan their upload folder for image file names
Code:
atahualpa_header_X.[jpg|gif|png|bmp] |
do you think it would be possible to automatically disable the html/css inserts for a wpmu installation? After the latest update I forgot again to manually disable it...
|
All times are GMT -6. The time now is 01:34 PM. |
Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.