Antville Project


(this time in english again ;-) as i figured out some (or all?) of the macros are too complex for users. if anyone of you has some idea how they should look like or how to simplify them (some, all ...), please tell me!


michi, July 5, 2001 at 11:53:41 AM CEST

the power of macros

the power of macros

Macros and Skins are neat for Designer and Layouter, but in my opinion a bit wrong placed for people who post stories and comments, since i don't see any smart way of how to restrict users to just use "safe" macros. And whatever restriction that is, can you be absolutely sure, that there are no security holes, that there is no way to produce infinite loops, and so on. On the other hand it is necessary to provide the admin of a weblog with that many macros in order to guarantee a maximum of customiation. So solutions could be: 1.) just stories and comments posted by the Admins are rendered as "skins", and otherwise just as plain text (i.e. the macros are not interpreted at all) 2.) we invent a new syntax for the functionality used by the posting users, which is basically link-creation and including images. e.g. link:url and image:name.

i would rather prefer the second option, but would like to hear other opinions on that. Of course the syntax of the second option is a whole complete topic on its own, which is also interesting to discuss about. but our experiences with iEdit might help here.


hns, July 5, 2001 at 1:04:32 PM CEST

Hold on...

While working with Tobi yesterday, I think I found a good way to restrict Macros in certain types of skins.

Some background: If you use some arbitrary text as skin, you call createSkin() with that text first (that's opposed to ordinary skins, which you can render by directly calling renderSkin()).

So my idea is to pass a second optional parameter to createSkin() which contains a list of allowed macros in that skin. This may be as a simple string, an array or something like that. The fact is that it's a simple solution, and you can specify the allowed macros at the right place: in the code that does handles text as skin.


... comment

The Antville Server Fund has been a great success. Thanks to everybody who contributed!
online for 8648 Days
last updated: 1/4/11, 10:22 AM
Youre not logged in ... Login
March 2025
zfuture's house here is zfuture's
by zfuture (7/31/03, 2:59 AM)
i understand your concerns however,
i hardly can think of a solution. certainly, if the...
by tobi (7/29/03, 9:47 AM)
Found several more similar sites
listed This is getting to be quite a concern to...
by cobalt123 (7/27/03, 7:56 PM)
Second Post Alert on Referrer
bug livecatz I put this into "help" and now here:...
by cobalt123 (7/26/03, 7:14 PM)
well it's not easy to
find from here, anyway. think we should include a link,...
by tobi (7/24/03, 11:25 AM)
So finally I found
the helma Bugzilla - stupid me.
by mdornseif (7/24/03, 10:28 AM)
clock not that it's particularly
earthshattering but the antclock is running slow by about 15...
by kohlehydrat (7/23/03, 8:25 PM)
but isn't can't really
be rated as spam can it?
by kohlehydrat (7/23/03, 8:08 PM)
More referrer spam
by Irene (7/23/03, 7:55 PM)
How to log skin names
I accessed to console?? Hi, I would like to know...
by winson (7/23/03, 4:12 PM)

Click here to get an XML version of this weblog.

Made with Antville
powered by
Helma Object Publisher