|
|
Joined: Jan 2003
Posts: 18
Newbie
|
|
Newbie
Joined: Jan 2003
Posts: 18 |
The lines in blue were copied from newreply.tmpl and added to [:"blue"] editpost.tmpl[/] (and to editpost_nopoll.tmpl). With these extra lines, the drop down box "Make post" and the four options [using UBBCode/using HTML/using HTML and UBBCode/without using HTML/UBBCode], which are available for new posts, are now available when editing a post. This allows html to be inserted, when a post is edited, even if it's not in the original post. <tr class="lighttable"> <td> {$ubbt_lang['SUBJECT_TEXT']} <br /> <input type="text" name="Subject" value="$Subject" maxlength="{$config['subjectlength']}" class="formboxes" size="60" /> $iconselect [:"blue"]$markupselect Edit post<br /><select name="convert" class="formboxes"><option value="markup" selected="selected">using UBBCode</option><option value="html">using HTML</option><option value="both">using HTML and UBBCode</option><option value="none">without UBBCode/HTML</option></select><br /><br />[/] {$ubbt_lang['POST_TEXT']} <br /> <textarea cols="$TextCols" rows="$TextRows" name="Body" class="formboxes" onkeyup="storeCaret(this);" onclick="storeCaret(this);">$Body</textarea> $instant_ubbcode <br /> This works when I edit a post and choose "using HTML and UBB code" from the drop down box, but fails when a mod uses it, or a member uses it (mods and members can see the drop-down box on the edit screen, but it doesn't "take", the post is still in ubb mode). What have I done wrong - do I need to add something else to editpost.tmpl, so that the drop-down box "takes" for mods and members? Our board is www.funtrivia.com/forums running v6.5b4 with thanks, from downhere! gt
|
|
|
|
|
Joined: Mar 2000
Posts: 528
Junior Member
|
|
Junior Member
Joined: Mar 2000
Posts: 528 |
Do you have HTML capability allowed for those groups via the board? I could be wrong without looking, but I believe the Admins can use HTML anytime they want, but the others can only use it if allowed.
Something to check at least...
|
|
|
|
|
Joined: Jan 2003
Posts: 18
Newbie
|
|
Newbie
Joined: Jan 2003
Posts: 18 |
yep, html is enabled in the forum where I want this to work. mate, I've tried everything, and thought that I'd solved it (I've been working on it, off and on, for a few weeks), until a mod tried it yesterday. There must be something, somewhere, which permits this edit to work for an admin, but no-one else .. but I can't find it, so I can modify it.
|
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
But if you didn't choose HTML when you made the post - you can't easily add html on edit without a Query. UPDATE w3t_Posts SET B_Markup = 'both' WHERE B_Number = xxxxxxx Use caution and make backups when doing direct db queries. 
|
|
|
|
|
Joined: Sep 2003
Posts: 488
Code Monkey
|
|
Code Monkey
Joined: Sep 2003
Posts: 488 |
I added this functionality to my boards (v6.3), and it's quite a bit more involved than you think. You've really gotta have a pretty good grasp of how things work imo. editpost.php requires a fair amount of changes, mostly with inserting new code chunks (including a new query), and modifypost.php also requires a couple changes too (including updating a query). The thing to keep in mind, is that you also want to have the pull-down menu select the originally entered value by default, and not merely default to the same for all of them which may inadvertently change people's selection when they are only correcting a typo or something. I would recommend that you hire someone to do this mod for you if you don't know how basically.
|
|
|
|
|
Joined: May 2004
Posts: 43
User
|
|
User
Joined: May 2004
Posts: 43 |
I have been working with gt on this for quite some time, and we just cannot figure it out. What we meant is, when an html post is made, only an administrator can edit it, otherwise, it comes out as normal code in the post. We have tried nearly everything, without success. The only way is to see for yourself. Try a post using html & ubb (which we have to use), then have a mod edit it. It does not work 
|
|
|
|
|
Joined: Jan 2003
Posts: 18
Newbie
|
|
Newbie
Joined: Jan 2003
Posts: 18 |
>> posted by JoshPet>> Use caution and make backups when doing direct db queries. yep, you've got me; I'm with you on that. The only SQL commands I've run are queries which do not change the db (all of the queries are in these fourms - allow me to take this opportunity to thank for for this marvelous site!) >> posted by Twisty>> I added this functionality to my boards (v6.3), and it's quite a bit more involved than you think. You've really gotta have a pretty good grasp of how things work imo. unquestionably .. and I'll freely admit I don't. This is way beyond my capabilities, and understanding.Your post confirms my suspicions that I was trying to put square pegs in a round hole. I don't want to play around with php files, as they're all unadulterated, as delivered. I think I'll abandon this, as it's an issue in only one forum, and I've gone off a tangent from the fundamental problem I've encountered. Similar problem: following on from what SG has posted (he's a member at our boards, and webmaster of another board, which also runs infopop) this was the fundamental problem we had, which I tried to fix by inserting those blue lines. When a member edited a post, the post would not retain its original settings; it'd revert to default [using UBBCode], e.g. a post which was made [using HTML and UBBCode] would come out in UBBCode only after the edit. To keep things running, I'd re-edit the post for them, and the original settings [using HTML and UBBCode] would be retained. If I wasn't around, some members would make a new post, rather than edit the original. This means that an admin can edit a post and the post would retain its original settings, but a member is unable to achieve the same result. I thought I'd solved that problem when I inserted the blue lines/drop down menu. Is it correct to say that there's a routine somewhere in infopop, which permits admins to edit a post and have it retain its original settings, but that routine is unavailable to members? What's required to ensure that the original settings of a post are retained when it's edited by a member - is there something I can insert into a tmpl file? we eat vegemite sandwiches downhere! 
|
|
|
|
|
Joined: Sep 2003
Posts: 488
Code Monkey
|
|
Code Monkey
Joined: Sep 2003
Posts: 488 |
[] gtho4 said: Is it correct to say that there's a routine somewhere in infopop, which permits admins to edit a post and have it retain its original settings, but that routine is unavailable to members? What's required to ensure that the original settings of a post are retained when it's edited by a member - is there something I can insert into a tmpl file? [/] Ok that better explains the situation. Imo that would have to be considered a bug because it shouldn't change the B_Convert field for non-admins when editing a post like that (assuming users have the right to post HTML). Anyway...you would have to alter modifypost.php to have it NOT update that field, it would not be done via the template alone. So if you want to do this, open modifypost.php and toward the bottom look for something like this... // ------------------- <br />// Update the database <br /> $Username_q = addslashes($user['U_Username']); <br /> $Icon_q = addslashes($Icon); <br /> $Subject_q = addslashes($Subject); <br /> $Body_q = addslashes($Body); <br /> $Body_q = preg_replace("/(\r\n|\n)/","<br />",$Body_q); <br /> <br /> $editdate_q = addslashes($editdate); <br /> $convert_q = addslashes($convert); <br /> <br /> $query = " <br /> UPDATE {$config['tbprefix']}Posts <br /> SET B_Subject = '$Subject_q', <br /> B_Convert = '$convert_q', <br /> B_Body = '$Body_q', <br /> B_Icon = '$Icon_q', <br /> B_LastEdit= '$editdate_q', <br /> B_LastEditBy = '$Username_q' <br /> $extra <br /> WHERE B_Number = '$Number' <br /> AND B_Board = '$Board_q' <br /> "; <br /> $dbh -> do_query($query); What you'll want to do is delete ... B_Convert = '$convert_q', Now again, I can't say for sure that this is exactly how the 6.5 script works but it has to be something very similar. The change req'd would be very small to alleviate the problem in either event. This won't allow you to have the functioning pull-down menu when editing the post which is a lot bigger job (so just delete the blue lines you added from above), but you won't really need to have it for the reason you wanted it anyway since it won't change from HTML to UBB anymore. If you still need more help, just let me know and I'll help you edit the script in private (on my own time), and then we can test the changes. Personally, I would go through with it because it must be incredibly annoying the way it behaves now 
|
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
I think that's by design - if a regular member edits a post with HTML (if they dont' have the ability to HTML) you want to "break it" otherwise they could insert dangerous stuff in the post. So it reverts to UBB If the post is HTML and everyone can post HTML - then the formatting should be retained. (If not then that's a bug) But allowing HTML in your forum to general users is a very bad and dangerous idea.  Youv'e got a high potential of getting hacked. 
|
|
|
|
|
Joined: Sep 2003
Posts: 488
Code Monkey
|
|
Code Monkey
Joined: Sep 2003
Posts: 488 |
[] JoshPet said: I think that's by design - if a regular member edits a post with HTML (if they dont' have the ability to HTML) you want to "break it" otherwise they could insert dangerous stuff in the post. So it reverts to UBB[/] Yep, that's basically what I was pointing out, if the users have the right to post HTML in newpost/newreply in the first place, then editing said post should not revert back to UBB only. Their 'rights' should remain constant. And since he says that he has not yet hacked any code, I can only assume that it's a bug. It's weird that modifypost is updating the B_Convert field like that in 6.5 though, it doesn't do that by default in 6.3, which imo is the way it should be with virgin scripts. *shrug* [] But allowing HTML in your forum to general users is a very bad and dangerous idea.  Youv'e got a high potential of getting hacked.  [/] I was going to mention something about this. Imo anyone who enables HTML for regular users without hacking in extra security measures (that's what I did) is playing Russian Roulette. It's not something I would personally do anyway. PS - Josh why do you of all people only have 4 stars?!? My god, what's going on here? *rates JoshPet 5 stars pronto* 
|
|
|
|
|
Joined: Jan 2003
Posts: 18
Newbie
|
|
Newbie
Joined: Jan 2003
Posts: 18 |
>> posted by JoshPet: >> But allowing HTML in your forum to general users is a very bad and dangerous idea >> posted by Twisty: >> Imo anyone who enables HTML for regular users without hacking in extra security measures (that's what I did) is playing Russian Roulette. It's not something I would personally do anyway. It scares me too, but it's needed in one of 20 forums - to line up numbers in tables. It's not a permanent setting - it's turned it off and on as and when one of the mods, SG, or myself require it to post a table. >> posted by Twisty: >> if the users have the right to post HTML in newpost/newreply in the first place, then editing said post should not revert back to UBB only. Their 'rights' should remain constant >> posted by JoshPet: >> If the post is HTML and everyone can post HTML - then the formatting should be retained. (If not then that's a bug) understood, looks like it's a bug. It also arises in this situation - a member posts using the setting [without using UBBCode/HTML], to show a newbie how to use ubb -- then edits the post to correct a typo. The post reverts to the default setting [using UBBCode], and the newbie is none the wiser. The member needs to repost afresh to correct this, so that the newbie can see the ubb code and how to use it. >> posted by Twisty: >> If you still need more help, just let me know and I'll help you edit the script in private (on my own time), and then we can test the changes. >> Personally, I would go through with it because it must be incredibly annoying the way it behaves now mate, I agree. I just hope it comes back in the next revision by infopop (I see it was aok in 6.3 but not 6.5). Thank you so much for your help, and thank you for the kind offer of your personal time but, as all php files are in their virgin as-delivered-state, I'll pass and wait for the next revision. In the interim, I'll take the blue lines out! Josh, my post in the Friday Test thread was made using the setting [without UBBCode/HTML] but failed, as the ubb code "took". I wanted to make that post using [without] and edit it, to see if the original settings were retained after an edit.
|
|
|
|
|
Joined: Nov 2002
Posts: 554
Code Monkey
|
|
Code Monkey
Joined: Nov 2002
Posts: 554 |
is there an sql command to disable html globally instead of having to do it in each forum? *edit* I did it!! I did it on my own!! And it worked ! I comprehend the world!! ok enough-here is what I did UPDATE w3t_Boards SET Bo_HTML = "Off" Was that right?
Last edited by ChAoS; 10/24/2004 12:01 PM.
|
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
Yup - that's right.
Admins and Mods can always post in HTML - if you just need table tags - then it'd be easier and safer to make UBBCode versions of [table] [tr] and [td]
One of those old extended markups mods had that I belive.
|
|
|
|
|
Joined: Nov 2002
Posts: 554
Code Monkey
|
|
Code Monkey
Joined: Nov 2002
Posts: 554 |
I never really knew HTML was such a huge security risk.I have had it enabled for 4 years now (and never used it once) so I guess I have been lucky
|
|
|
|
|
Joined: Jan 2003
Posts: 18
Newbie
|
|
Newbie
Joined: Jan 2003
Posts: 18 |
[]JoshPet said: if you just need table tags - then it'd be easier and safer to make UBBCode versions of [table] [tr] and [td]
One of those old extended markups mods had that I believe. [/] thanks mate, that's much safer. I'll start looking into it (I wasn't aware there were ubb equivalents). Hopefully I don't need to be a rocket scientist to understand/create those extensions.
|
|
|
|
|
Joined: Jan 2005
Posts: 1
Lurker
|
|
Lurker
Joined: Jan 2005
Posts: 1 |
[] Twisty said:What you'll want to do is delete ... B_Convert = '$convert_q', Now again, I can't say for sure that this is exactly how the 6.5 script works but it has to be something very similar.[/] I ran into this on a board i frequent; in 6.5 reguardless of your html on/off settings it it hard-coded that only Administrator can edit a post in html, all others are escaped prior to the database update  modifypost.php (line 175) <br />// -----------------------------------------------------<br />// If HTML is off then we get rid of < and > in the body<br />if ( [:"red"]($user['U_Status'] != "Administrator")[/] || ( ($convert != "html") && ($convert != "both") ) ){<br />$PrintBody = str_replace("<","& lt;",$PrintBody);<br />$PrintBody = str_replace(">","& gt;",$PrintBody);<br />}<br />else {<br />$PrintBody = preg_replace("/<!--(.|\n)*-->/","",$PrintBody);<br />}<br />
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 87
Joined: December 2001
|
|
|
Forums63
Topics37,583
Posts293,955
Members13,825
| |
Most Online151,614 Nov 14th, 2025
|
|
Currently Online 6968
Topics Created 0
Posts Made 0
Users Online 0
Birthdays 7
|
|
|
|