View Issue Details

This issue affects 1 person(s).
 0
IDProjectCategoryView StatusLast Update
20504Feature requestsTranslationpublic2026-04-28 09:36
Reporterriqcles Assigned To 
PrioritynoneSeverityfeature 
Status newResolutionopen 
Summary20504: change text : Disable question script for XSS restricted user
Description

In the security menu, the choice for this option is ambiguous.
And the translation into French (and perhaps other languages) doesn't help in making the right choice.

I suggest:
Changing the text of the option
Disable question script for XSS restricted user
to:
Disable the use of XSS scripting in questions for users with restricted rights:

Which would read in French:

Désactiver l'utilisation de script XSS dans les questions pour les utilisateurs avec des droits restrictins:

Then the help text:
If you disable this option: user with XSS restriction still can add script. This allows user to add cross-site scripting javascript system.

Then add the word "WARNING" in bold at the beginning of the sentence, as in the "Force HTTPS" section.

Which would read:
WARNING: If you disable this option: user with XSS restriction still can add script. This allows the user to add cross-site scripting to the JavaScript system.

This will avoid any misunderstandings.

Additional Information

and in global setting --> Security , for :

Filter HTML for XSS:

and
Disable question script for XSS restricted user:

No french (other ?) translation when the settings 'filterxsshtml_forcedall' (other ?) are enabled in the config.php file

TagsNo tags attached.
Bug heat0
Story point estimate0
Users affected %0

Users monitoring this issue

There are no users monitoring this issue.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-04-28 09:36 riqcles New Issue