[Building Sakai] Javascript in MOTD

Daniel Merino daniel.merino at unavarra.es
Tue Mar 15 04:32:19 PDT 2011


Hi everybody.

I'm trying, as admin user, to make a Message of the Day announcement 
with a flash video embedded inside it.

When I try to save the HTML code embedding the video, I receive error 
messages that says me "The HTML attribute pattern ' flashvars (...)' is 
not allowed". This attribute is at the tag "embed".

Trying to make an HTML page in Resources (where javascript is allowed) 
and embedding it into Announcements gives me another error: "The HTML 
tag <iframe> is not allowed"...

I can understand that Sakai platform must be protected against XSS 
attacks, but it has no sense to me to forbid the javascript to the admin 
user, even less in MOTD, a tool only available to admin users.

So I wonder if I can disable the javascript protection for the admin 
user in some way, or if somebody knows any trick to jump over this 
protection. Does anybody know how could I do this?

Thanks in advance.
Best regards.
-- 
Daniel Merino
daniel.merino at unavarra.es
Gestor de teleformación - Centro Superior de Innovación Educativa.
Tfno: 948-168489 - Universidad Pública de Navarra.


More information about the sakai-dev mailing list