<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet href="http://bugs.horde.org/themes/feed-rss.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
 <channel>
  <title>HTML messages created with IMP and FCKEDIT have formatting stripped while viewing with IE6/7 </title>
  <pubDate>Sat, 22 Nov 2008 12:04:38 -0500</pubDate>
  <link>http://bugs.horde.org/ticket/6891</link>
  <atom:link rel="self" type="application/rss+xml" title="HTML messages created with IMP and FCKEDIT have formatting stripped while viewing with IE6/7 " href="http://bugs.horde.org/ticket/6891/rss" />
  <description>HTML messages created with IMP and FCKEDIT have formatting stripped while viewing with IE6/7 </description>

  
  
  <item>
   <title>If you receive an HTML formatted message created in IMP..  w</title>
   <description>If you receive an HTML formatted message created in IMP..  when you view it in IE6/7, IMP will strip some of the formatting in the name of protecting us from XSS...

&lt;h1&gt;&lt;span XSSCleaned=&quot;color: rgb(255, 0, 0);&quot;&gt;&lt;strong&gt;
&lt;span XSSCleaned=&quot;font-size: xx-large;&quot;&gt;
&lt;span XSSCleaned=&quot;font-family: Verdana;&quot;&gt;Red&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/h1&gt;

You can view the message properly using the same IMP installation and other browsers / platforms.   The problem mostly seems to be with &quot;spans&quot; and &quot;styles&quot;.  I've also seen it strip formatting from Mail.app messages.</description>
   <pubDate>Tue, 10 Jun 2008 15:16:08 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6891#t46210</link>
  </item>
  <item>
   <title>What's the bug/action here though? IE allows javascript in i</title>
   <description>What's the bug/action here though? IE allows javascript in inline styles (expression: ...), so we have to strip them.</description>
   <pubDate>Tue, 10 Jun 2008 15:26:01 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6891#t46212</link>
  </item>
  <item>
   <title>Ah. 

Is this documented someplace?  (e.g. &quot;When using IE,</title>
   <description>Ah. 

Is this documented someplace?  (e.g. &quot;When using IE, we strip some formating because IE allows JS to be embedded in style information...&quot;)

Mostly, I think our help desk was expecting the same messages to be displayed the same across browsers.. and I was surprised that IMP + IE was filtering some stuff in the name of XSS protection, when it wasn't on other browsers.</description>
   <pubDate>Tue, 10 Jun 2008 15:45:18 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6891#t46214</link>
  </item>
  <item>
   <title>&gt; Is this documented someplace?  (e.g. &quot;When using IE, we st</title>
   <description>&gt; Is this documented someplace?  (e.g. &quot;When using IE, we strip some 
&gt; formating because IE allows JS to be embedded in style 
&gt; information...&quot;)

Probably not anywhere user-visible. Suggestions on where that might usefully go would be welcome.</description>
   <pubDate>Thu, 12 Jun 2008 14:32:07 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6891#t46342</link>
  </item>
  <item>
   <title>Not closing out the possibility of doc improvements, but we </title>
   <description>Not closing out the possibility of doc improvements, but we can either reopen this, or you can post them elsewhere.</description>
   <pubDate>Mon, 30 Jun 2008 14:55:59 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6891#t47027</link>
  </item>
  

 </channel>
</rss>
