A
A
Andrey Mensky2015-03-17 15:18:40
symfony
Andrey Mensky, 2015-03-17 15:18:40

What are the intricacies of implementing Symfony2 + Twig custom templates?

Good afternoon comrades.
There is a task to implement the ability to edit the appearance of the user's personal page, up to a complete change in the html structure. Trite to make a form with a textarea and then send it to the twig service for rendering seems like a completely unsafe idea. Perhaps you should remove global variables and disable most functions.
Who faced similar?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
A
Alexey Pavlov, 2015-03-17
@lexxpavlov

Try to give the user the ability to write their own HTML, but limit the possibilities with HTMLPurifier -a (about it on Habré , there is a bundle ). It seems to be secure enough that the user cannot enter anything dangerous. Give him the opportunity to enter the main html tags and classes, and the appearance - in a separate css.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question