markdown.html 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281
  1. {% extends '../layout/admin.html' %}
  2. {% block html_title %}{{ customizeService.generateCustomTitle(t('Markdown settings')) }}
  3. · {{ path }}{% endblock %}
  4. {% block content_header %}
  5. <div class="header-wrap">
  6. <header id="page-header">
  7. <h1 id="admin-title" class="title">{{ t('Markdown settings') }}</h1>
  8. </header>
  9. </div>
  10. {% endblock %}
  11. {% block content_main %}
  12. <div class="content-main">
  13. <div class="row">
  14. <div class="col-md-3">
  15. {% include './widget/menu.html' with {current: 'markdown'} %}
  16. </div>
  17. <!-- TODO reactify admin -->
  18. <div class="col-md-9">
  19. {% set smessage = req.flash('successMessage') %}
  20. {% if smessage.length %}
  21. <div class="alert alert-success">
  22. {% for e in smessage %}
  23. {{ e }}<br>
  24. {% endfor %}
  25. </div>
  26. {% endif %}
  27. {% set emessage = req.flash('errorMessage') %}
  28. {% if emessage.length %}
  29. <div class="alert alert-danger">
  30. {% for e in emessage %}
  31. {{ e }}<br>
  32. {% endfor %}
  33. </div>
  34. {% endif %}
  35. <form action="/admin/markdown/lineBreaksSetting" method="post" class="form-horizontal" id="markdownSettingForm" role="form">
  36. <fieldset>
  37. <legend>{{ t('markdown_setting.line_break_setting') }}</legend>
  38. <p class="well">{{ t("markdown_setting.line_break_setting_desc") }}</p>
  39. <div class="form-group">
  40. <label for="markdownSetting[markdown:isEnabledLinebreaks]" class="col-xs-4 control-label">
  41. {{ t('markdown_setting.Enable Line Break') }}
  42. </label>
  43. <div class="col-xs-5">
  44. <div class="btn-group btn-toggle" data-toggle="buttons">
  45. <label class="btn btn-default btn-rounded btn-outline {% if markdownSetting['markdown:isEnabledLinebreaks'] %}active{% endif %}" data-active-class="primary">
  46. <input name="markdownSetting[markdown:isEnabledLinebreaks]" value="true" type="radio"
  47. {% if true === markdownSetting['markdown:isEnabledLinebreaks'] %}checked{% endif %}> ON
  48. </label>
  49. <label class="btn btn-default btn-rounded btn-outline {% if !markdownSetting['markdown:isEnabledLinebreaks'] %}active{% endif %}" data-active-class="default">
  50. <input name="markdownSetting[markdown:isEnabledLinebreaks]" value="false" type="radio"
  51. {% if !markdownSetting['markdown:isEnabledLinebreaks'] %}checked{% endif %}> OFF
  52. </label>
  53. </div>
  54. <p class="help-block">{{ t("markdown_setting.Enable Line Break desc") }}</p>
  55. </div>
  56. </div>
  57. <div class="form-group">
  58. <label for="markdownSetting[markdown:isEnabledLinebreaksInComments]" class="col-xs-4 control-label">
  59. {{ t("markdown_setting.Enable Line Break for comment") }}
  60. </label>
  61. <div class="col-xs-5">
  62. <div class="btn-group btn-toggle" data-toggle="buttons">
  63. <label class="btn btn-default btn-rounded btn-outline {% if markdownSetting['markdown:isEnabledLinebreaksInComments'] %}active{% endif %}" data-active-class="primary">
  64. <input name="markdownSetting[markdown:isEnabledLinebreaksInComments]" value="true" type="radio"
  65. {% if true === markdownSetting['markdown:isEnabledLinebreaksInComments'] %}checked{% endif %}> ON
  66. </label>
  67. <label class="btn btn-default btn-rounded btn-outline {% if !markdownSetting['markdown:isEnabledLinebreaksInComments'] %}active{% endif %}" data-active-class="default">
  68. <input name="markdownSetting[markdown:isEnabledLinebreaksInComments]" value="false" type="radio"
  69. {% if !markdownSetting['markdown:isEnabledLinebreaksInComments'] %}checked{% endif %}> OFF
  70. </label>
  71. </div>
  72. <p class="help-block">{{ t("markdown_setting.Enable Line Break for comment desc") }}</p>
  73. </div>
  74. </div>
  75. <div class="form-group my-3">
  76. <div class="col-xs-offset-4 col-xs-5">
  77. <input type="hidden" name="_csrf" value="{{ csrf() }}">
  78. <button type="submit" class="btn btn-primary">{{ t("Update") }}</button>
  79. </div>
  80. </div>
  81. </fieldset>
  82. </form>
  83. <form action="/admin/markdown/presentationSetting" method="post" class="form-horizontal" id="markdownSettingForm" role="form">
  84. <legend>{{ t('markdown_setting.presentation_setting') }}</legend>
  85. <p class="well">{{ t("markdown_setting.presentation_setting_desc") }}</p>
  86. <fieldset class="form-group row my-2">
  87. {% set nameForPageBreakOption = "markdownSetting[markdown:presentation:pageBreakSeparator]" %}
  88. {% set pageBreakSeparator = markdownSetting['markdown:presentation:pageBreakSeparator'] %}
  89. <label class="col-xs-3 control-label">
  90. {{ t('markdown_setting.Page break setting') }}
  91. </label>
  92. <div class="col-xs-3 radio radio-primary">
  93. <input type="radio" id="pageBreakOption1" name="{{nameForPageBreakOption}}" value="1" {% if pageBreakSeparator === 1 %}checked{% endif %}>
  94. <label for="pageBreakOption1">
  95. <p class="font-weight-bold">{{ t('markdown_setting.Preset one separator') }}</p>
  96. <p class="mt-3">
  97. {{ t('markdown_setting.Preset one separator desc') }}
  98. <pre><code>{{ t('markdown_setting.Preset one separator value') }}</code></pre>
  99. </p>
  100. </label>
  101. </div>
  102. <div class="col-xs-3 radio radio-primary">
  103. <input type="radio" id="pageBreakOption2" name="{{nameForPageBreakOption}}" value="2" {% if pageBreakSeparator === 2 %}checked{% endif %}>
  104. <label for="pageBreakOption2">
  105. <p class="font-weight-bold">{{ t('markdown_setting.Preset two separator') }}</p>
  106. <p class="mt-3">
  107. {{ t('markdown_setting.Preset two separator desc') }}
  108. <pre><code>{{ t('markdown_setting.Preset two separator value') }}</code></pre>
  109. </p>
  110. </label>
  111. </div>
  112. <div class="col-xs-3 radio radio-primary">
  113. <input type="radio" id="pageBreakOption3" name="{{nameForPageBreakOption}}" value="3" {% if pageBreakSeparator === 3 %}checked{% endif %}>
  114. <label for="pageBreakOption3">
  115. <p class="font-weight-bold">{{ t('markdown_setting.Custom separator') }}</p>
  116. <p class="mt-3">
  117. {{ t('markdown_setting.Custom separator desc') }}
  118. <div>
  119. <input class="form-control" name="markdownSetting[markdown:presentation:pageBreakCustomSeparator]" value="{{markdownSetting['markdown:presentation:pageBreakCustomSeparator']|default('') }}">
  120. </div>
  121. </p>
  122. </label>
  123. </div>
  124. </fieldset>
  125. <div class="form-group my-3">
  126. <div class="col-xs-offset-4 col-xs-5">
  127. <input type="hidden" name="_csrf" value="{{ csrf() }}">
  128. <button type="submit" class="btn btn-primary">{{ t("Update") }}</button>
  129. </div>
  130. </div>
  131. </form>
  132. <form action="/admin/markdown/xss-setting" method="post" class="form-horizontal" id="markdownSettingForm" role="form">
  133. {% set nameForIsXssEnabled = "markdownSetting[markdown:xss:isEnabledPrevention]" %}
  134. {% set isXssEnabled = markdownSetting['markdown:xss:isEnabledPrevention'] %}
  135. <legend>{{ t('markdown_setting.XSS_setting') }}</legend>
  136. <p class="well">{{ t("markdown_setting.XSS_setting_desc") }}</p>
  137. <fieldset class="row">
  138. <div class="form-group">
  139. <label for="markdownSetting[markdown:isEnabledLinebreaks]" class="col-xs-4 control-label">
  140. {{ t('markdown_setting.Enable XSS prevention') }}
  141. </label>
  142. <div class="col-xs-5">
  143. <div class="btn-group btn-toggle" data-toggle="buttons">
  144. <label class="btn btn-default btn-rounded btn-outline {% if isXssEnabled %}active{% endif %}" data-active-class="primary">
  145. <input name="{{nameForIsXssEnabled}}" value="true" type="radio"
  146. {% if isXssEnabled %}checked{% endif %}> ON
  147. </label>
  148. <label class="btn btn-default btn-rounded btn-outline {% if !isXssEnabled %}active{% endif %}" data-active-class="default">
  149. <input name="{{nameForIsXssEnabled}}" value="false" type="radio"
  150. {% if !isXssEnabled %}checked{% endif %}> OFF
  151. </label>
  152. </div>
  153. </div>
  154. </div>
  155. </fieldset>
  156. <fieldset class="form-group row my-3" id="xss-hide-when-disabled" {% if !isXssEnabled %}style="display: none;"{% endif %}>
  157. {% set nameForXssOption = "markdownSetting[markdown:xss:option]" %}
  158. {% set xssOption = markdownSetting['markdown:xss:option'] %}
  159. <div class="col-xs-4 radio radio-primary">
  160. <input type="radio" id="xssOption1" name="{{nameForXssOption}}" value="1" {% if xssOption === 1 %}checked{% endif %}>
  161. <label for="xssOption1">
  162. <p class="font-weight-bold">{{ t('markdown_setting.Ignore all tags') }}</p>
  163. <div class="m-t-15">
  164. {{ t('markdown_setting.Ignore all tags desc') }}
  165. </div>
  166. </label>
  167. </div>
  168. <div class="col-xs-4 radio radio-primary">
  169. <input type="radio" id="xssOption2" name="{{nameForXssOption}}" value="2" {% if xssOption === 2 %}checked{% endif %}>
  170. <label for="xssOption2">
  171. <p class="font-weight-bold">{{ t('markdown_setting.Recommended setting') }}</p>
  172. <div class="m-t-15">
  173. {{ t('markdown_setting.Tag names') }}
  174. <textarea class="form-control xss-list" name="recommendedTags" rows="6" cols="40" readonly>{{ recommendedWhitelist.tags }}</textarea>
  175. </div>
  176. <div class="m-t-15">
  177. {{ t('markdown_setting.Tag attributes') }}
  178. <textarea class="form-control xss-list" name="recommendedAttrs" rows="6" cols="40" readonly>{{ recommendedWhitelist.attrs }}</textarea>
  179. </div>
  180. </label>
  181. </div>
  182. <div class="col-xs-4 radio radio-primary">
  183. <input type="radio" id="xssOption3" name="{{nameForXssOption}}" value="3" {% if xssOption === 3 %}checked{% endif %}>
  184. <label for="xssOption3">
  185. <p class="font-weight-bold">{{ t('markdown_setting.Custom Whitelist') }}</p>
  186. <div class="m-t-15">
  187. <div class="d-flex justify-content-between">
  188. {{ t('markdown_setting.Tag names') }}
  189. <p id="btn-import-tags" class="btn btn-xs btn-primary">
  190. {{ t('markdown_setting.import_recommended', 'tags') }}
  191. </p>
  192. </div>
  193. <textarea class="form-control xss-list" type="text" name="markdownSetting[markdown:xss:tagWhiteList]" rows="6" cols="40" placeholder="e.g. iframe, script, video...">{{ markdownSetting['markdown:xss:tagWhiteList'] }}</textarea>
  194. </div>
  195. <div class="m-t-15">
  196. <div class="d-flex justify-content-between">
  197. {{ t('markdown_setting.Tag attributes') }}
  198. <p id="btn-import-attrs" class="btn btn-xs btn-primary">
  199. {{ t('markdown_setting.import_recommended', 'attributes') }}
  200. </p>
  201. </div>
  202. <textarea class="form-control xss-list" name="markdownSetting[markdown:xss:attrWhiteList]" rows="6" cols="40" placeholder="e.g. src, id, name...">{{ markdownSetting['markdown:xss:attrWhiteList'] }}</textarea>
  203. </div>
  204. </label>
  205. </div>
  206. </fieldset>
  207. <div class="form-group row">
  208. <div class="col-xs-12 d-flex justify-content-center">
  209. <input type="hidden" name="_csrf" value="{{ csrf() }}">
  210. <button type="submit" class="btn btn-primary">{{ t("Update") }}</button>
  211. </div>
  212. </div>
  213. </form>
  214. </div>
  215. </div>
  216. </div>
  217. <script>
  218. // give a space between items in textarea(',' => ', ')
  219. for (var i = 0; i < $('textarea.xss-list').length; i++) {
  220. $($('textarea.xss-list')[i]).val($($('textarea.xss-list')[i]).val().replace(/,/g, ', '));
  221. };
  222. $('input[name="markdownSetting[markdown:xss:isEnabledPrevention]"]').change(function() {
  223. if ($(this).val() === 'true') {
  224. $('#xss-hide-when-disabled').slideDown();
  225. }
  226. else {
  227. $('#xss-hide-when-disabled').slideUp();
  228. }
  229. });
  230. $('#btn-import-tags').on('click', () => {
  231. var $tagWhiteList = $('textarea[name="markdownSetting[markdown:xss:tagWhiteList]"]');
  232. var $recommendedTagList = $('textarea[name="recommendedTags"]');
  233. $tagWhiteList.val($recommendedTagList.val());
  234. });
  235. $('#btn-import-attrs').on('click', () => {
  236. var $attrWhiteList = $('textarea[name="markdownSetting[markdown:xss:attrWhiteList]"]');
  237. var $recommendedAttrList = $('textarea[name="recommendedAttrs"]');
  238. $attrWhiteList.val($recommendedAttrList.val());
  239. });
  240. </script>
  241. {% endblock content_main %}
  242. {% block content_footer %}
  243. {% endblock content_footer %}