markdown.html 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251
  1. {% extends '../layout/admin.html' %}
  2. {% block html_title %}{{ customTitle(t('Markdown settings')) }}
  3. · {{ path }}{% endblock %}
  4. {% block content_header %}
  5. <div class="header-wrap">
  6. <header id="page-header">
  7. <h1 class="title" id="">{{ t('Markdown settings') }}</h1>
  8. </header>
  9. </div>
  10. {% endblock %}
  11. {% block content_main %}
  12. <div class="content-main">
  13. <div class="row">
  14. <div class="col-md-3">
  15. {% include './widget/menu.html' with {current: 'markdown'} %}
  16. </div>
  17. <div class="col-md-9">
  18. {% set smessage = req.flash('successMessage') %}
  19. {% if smessage.length %}
  20. <div class="alert alert-success">
  21. {% for e in smessage %}
  22. {{ e }}<br>
  23. {% endfor %}
  24. </div>
  25. {% endif %}
  26. {% set emessage = req.flash('errorMessage') %}
  27. {% if emessage.length %}
  28. <div class="alert alert-danger">
  29. {% for e in emessage %}
  30. {{ e }}<br>
  31. {% endfor %}
  32. </div>
  33. {% endif %}
  34. <form action="/admin/markdown/lineBreaksSetting" method="post" class="form-horizontal" id="markdownSettingForm" role="form">
  35. <fieldset>
  36. <legend>{{ t('markdown_setting.line_break_setting') }}</legend>
  37. <p class="well">{{ t("markdown_setting.line_break_setting_desc") }}</p>
  38. <div class="form-group">
  39. <label for="markdownSetting[markdown:isEnabledLinebreaks]" class="col-xs-4 control-label">
  40. {{ t('markdown_setting.Enable Line Break') }}
  41. </label>
  42. <div class="col-xs-5">
  43. <div class="btn-group btn-toggle" data-toggle="buttons">
  44. <label class="btn btn-default btn-rounded btn-outline {% if markdownSetting['markdown:isEnabledLinebreaks'] %}active{% endif %}" data-active-class="primary">
  45. <input name="markdownSetting[markdown:isEnabledLinebreaks]" value="true" type="radio"
  46. {% if true === markdownSetting['markdown:isEnabledLinebreaks'] %}checked{% endif %}> ON
  47. </label>
  48. <label class="btn btn-default btn-rounded btn-outline {% if !markdownSetting['markdown:isEnabledLinebreaks'] %}active{% endif %}" data-active-class="default">
  49. <input name="markdownSetting[markdown:isEnabledLinebreaks]" value="false" type="radio"
  50. {% if !markdownSetting['markdown:isEnabledLinebreaks'] %}checked{% endif %}> OFF
  51. </label>
  52. </div>
  53. <p class="help-block">{{ t("markdown_setting.Enable Line Break desc") }}</p>
  54. </div>
  55. </div>
  56. <div class="form-group">
  57. <label for="markdownSetting[markdown:isEnabledLinebreaksInComments]" class="col-xs-4 control-label">
  58. {{ t("markdown_setting.Enable Line Break for comment") }}
  59. </label>
  60. <div class="col-xs-5">
  61. <div class="btn-group btn-toggle" data-toggle="buttons">
  62. <label class="btn btn-default btn-rounded btn-outline {% if markdownSetting['markdown:isEnabledLinebreaksInComments'] %}active{% endif %}" data-active-class="primary">
  63. <input name="markdownSetting[markdown:isEnabledLinebreaksInComments]" value="true" type="radio"
  64. {% if true === markdownSetting['markdown:isEnabledLinebreaksInComments'] %}checked{% endif %}> ON
  65. </label>
  66. <label class="btn btn-default btn-rounded btn-outline {% if !markdownSetting['markdown:isEnabledLinebreaksInComments'] %}active{% endif %}" data-active-class="default">
  67. <input name="markdownSetting[markdown:isEnabledLinebreaksInComments]" value="false" type="radio"
  68. {% if !markdownSetting['markdown:isEnabledLinebreaksInComments'] %}checked{% endif %}> OFF
  69. </label>
  70. </div>
  71. <p class="help-block">{{ t("markdown_setting.Enable Line Break for comment desc") }}</p>
  72. </div>
  73. </div>
  74. <div class="form-group my-3">
  75. <div class="col-xs-offset-4 col-xs-5">
  76. <input type="hidden" name="_csrf" value="{{ csrf() }}">
  77. <button type="submit" class="btn btn-primary">{{ t("Update") }}</button>
  78. </div>
  79. </div>
  80. </fieldset>
  81. </form>
  82. <form action="/admin/markdown/xss-setting" method="post" class="form-horizontal" id="markdownSettingForm" role="form">
  83. {% set nameForIsXssEnabled = "markdownSetting[markdown:xss:isPrevented]" %}
  84. {% set isXssEnabled = markdownSetting['markdown:xss:isPrevented'] %}
  85. <fieldset>
  86. <legend>{{ t('markdown_setting.XSS_setting') }}</legend>
  87. <p class="well">{{ t("markdown_setting.XSS_setting_desc") }}</p>
  88. <label for="{{nameForIsXssEnabled}}" class="col-xs-4 control-label">
  89. {{ t('markdown_setting.Prevent XSS(Cross Site Scripting)') }}
  90. </label>
  91. <div class="col-xs-5">
  92. <div class="form-group">
  93. <div class="col-xs-6">
  94. <div class="btn-group btn-toggle" data-toggle="buttons">
  95. <label class="btn btn-default btn-rounded btn-outline {% if isXssEnabled %}active{% endif %}" data-active-class="primary">
  96. <input name="{{nameForIsXssEnabled}}" value="true" type="radio"
  97. {% if isXssEnabled %}checked{% endif %}> ON
  98. </label>
  99. <label class="btn btn-default btn-rounded btn-outline {% if !isXssEnabled %}active{% endif %}" data-active-class="default">
  100. <input name="{{nameForIsXssEnabled}}" value="false" type="radio"
  101. {% if !isXssEnabled %}checked{% endif %}> OFF
  102. </label>
  103. </div>
  104. </div>
  105. </div>
  106. <fieldset id="xss-hide-when-disabled" {% if !isXssEnabled %}style="display: none;"{% endif %}>
  107. {% set nameForXssOption = "markdownSetting[markdown:xss:option]" %}
  108. {% set xssOption = markdownSetting['markdown:xss:option'] %}
  109. <div class="form-group">
  110. <div class="col-xs-6">
  111. <div class="btn-group btn-toggle" data-toggle="buttons">
  112. <div>
  113. <label data-active-class="primary">
  114. <input name="{{nameForXssOption}}" value="1" type="radio"
  115. {% if xssOption === 1 %}checked{% endif %}>
  116. {{ t('markdown_setting.Ignore all tags') }}
  117. </label>
  118. </div>
  119. <div>
  120. <label data-active-class="primary">
  121. <input name="{{nameForXssOption}}" value="2" type="radio"
  122. {% if xssOption === 2 %}checked{% endif %}>
  123. {{ t('markdown_setting.Recommended setting') }}<br>
  124. </label>
  125. </div>
  126. <div>
  127. <label data-active-class="primary">
  128. <input name="{{nameForXssOption}}" value="3" type="radio"
  129. {% if xssOption === 3 %}checked{% endif %}>
  130. {{ t('markdown_setting.Custom Whitelist') }}
  131. </label>
  132. </div>
  133. </div>
  134. </div>
  135. </div>
  136. <div class="form-group" id="xss2-hide-when-disabled" {% if !isXssEnabled || (xssOption !== 2) %}style="display: none;"{% endif %}>
  137. <div>
  138. {{ t('markdown_setting.Tag names') }}
  139. <div>
  140. <textarea class="form-control" type="text" name="recommendedTags" rows="5" cols="40" readonly>{{ markdownSetting['markdown:xss:recommendedTagWhiteList'] }}</textarea>
  141. </div>
  142. </div>
  143. <div>
  144. {{ t('markdown_setting.Tag attributes') }}
  145. <div>
  146. <textarea class="form-control" name="recommendedAttrs" rows="5" cols="40" readonly>{{ markdownSetting['markdown:xss:recommendedAttrWhiteList'] }}</textarea>
  147. </div>
  148. </div>
  149. </div>
  150. <div class="form-group" id="xss3-hide-when-disabled" {% if !isXssEnabled || (xssOption !== 3) %}style="display: none;"{% endif %}>
  151. <div>
  152. {{ t('markdown_setting.Tag names') }}
  153. <div>
  154. <textarea class="form-control" type="text" name="markdownSetting[markdown:xss:tagWhiteList]" rows="5" cols="40" placeholder="e.g. iframe, script, video...">{{ markdownSetting['markdown:xss:tagWhiteList'] }}</textarea>
  155. <input type="button" id="btn-import-tags" class="btn btn-default" value="{{ t('markdown_setting.import_recommended', 'tags') }}" />
  156. </div>
  157. </div>
  158. <div>
  159. {{ t('markdown_setting.Tag attributes') }}
  160. <div>
  161. <textarea class="form-control" name="markdownSetting[markdown:xss:attrWhiteList]" rows="5" cols="40" placeholder="e.g. src, id, name...">{{ markdownSetting['markdown:xss:attrWhiteList'] }}</textarea>
  162. <input type="button" id="btn-import-attrs" class="btn btn-default" value="{{ t('markdown_setting.import_recommended', 'attributes') }}" />
  163. </div>
  164. </div>
  165. </div>
  166. </fieldset>
  167. <div class="form-group my-3">
  168. <div class="col-xs-5">
  169. <input type="hidden" name="_csrf" value="{{ csrf() }}">
  170. <button type="submit" class="btn btn-primary">{{ t("Update") }}</button>
  171. </div>
  172. </div>
  173. </div>
  174. </fieldset>
  175. </form>
  176. </div>
  177. </div>
  178. </div>
  179. <script>
  180. $('input[name="markdownSetting[markdown:xss:isPrevented]"]').change(function() {
  181. if ($(this).val()) {
  182. $('#xss-hide-when-disabled').show(400);
  183. switch($('input[name="markdownSetting[markdown:xss:option]"]:checked').val()) {
  184. case '1':
  185. console.log(1)
  186. break;
  187. case '2':
  188. console.log(2)
  189. break;
  190. case '3':
  191. console.log(3)
  192. break;
  193. default:
  194. }
  195. }
  196. else {
  197. $('#xss-hide-when-disabled').hide(400);
  198. }
  199. });
  200. $('input[name="markdownSetting[markdown:xss:option]"]').change(function() {
  201. if ($(this).val() === "1") {
  202. $('#xss2-hide-when-disabled').hide(400);
  203. $('#xss3-hide-when-disabled').hide(400);
  204. }
  205. else if ($(this).val() === "2") {
  206. $('#xss2-hide-when-disabled').show(400);
  207. $('#xss3-hide-when-disabled').hide(400);
  208. }
  209. else {
  210. $('#xss3-hide-when-disabled').show(400);
  211. $('#xss2-hide-when-disabled').hide(400);
  212. }
  213. });
  214. $('#btn-import-attrs')
  215. </script>
  216. {% endblock content_main %}
  217. {% block content_footer %}
  218. {% endblock content_footer %}