Answer the question
In order to leave comments, you need to log in
What are the intricacies of implementing Symfony2 + Twig custom templates?
Good afternoon comrades.
There is a task to implement the ability to edit the appearance of the user's personal page, up to a complete change in the html structure. Trite to make a form with a textarea and then send it to the twig service for rendering seems like a completely unsafe idea. Perhaps you should remove global variables and disable most functions.
Who faced similar?
Answer the question
In order to leave comments, you need to log in
Try to give the user the ability to write their own HTML, but limit the possibilities with HTMLPurifier -a (about it on Habré , there is a bundle ). It seems to be secure enough that the user cannot enter anything dangerous. Give him the opportunity to enter the main html tags and classes, and the appearance - in a separate css.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question