View Issue Details

This issue affects 1 person(s).
 2
IDProjectCategoryView StatusLast Update
20504Feature requestsTranslationpublic2026-04-28 16:46
Reporterriqcles Assigned To 
PrioritynoneSeverityfeature 
Status newResolutionopen 
Summary20504: change text : Disable question script for XSS restricted user
Description

In the security menu, the choice for this option is ambiguous.
And the translation into French (and perhaps other languages) doesn't help in making the right choice.

I suggest:
Changing the text of the option
Disable question script for XSS restricted user
to:
Disable the use of XSS scripting in questions for users with restricted rights:

Which would read in French:

Désactiver l'utilisation de script XSS dans les questions pour les utilisateurs avec des droits restrictins:

Then the help text:
If you disable this option: user with XSS restriction still can add script. This allows user to add cross-site scripting javascript system.

Then add the word "WARNING" in bold at the beginning of the sentence, as in the "Force HTTPS" section.

Which would read:
WARNING: If you disable this option: user with XSS restriction still can add script. This allows the user to add cross-site scripting to the JavaScript system.

This will avoid any misunderstandings.

Additional Information

and in global setting --> Security , for :

Filter HTML for XSS:

and
Disable question script for XSS restricted user:

No french (other ?) translation when the settings 'filterxsshtml_forcedall' (other ?) are enabled in the config.php file

TagsNo tags attached.
Bug heat2
Story point estimate0
Users affected %0

Users monitoring this issue

There are no users monitoring this issue.

Activities

raymondoyondi

raymondoyondi

2026-04-28 16:46

developer   ~84751

I'd like to work on this issue. Can I get assigned this please?

Issue History

Date Modified Username Field Change
2026-04-28 09:36 riqcles New Issue
2026-04-28 16:46 raymondoyondi Note Added: 84751
2026-04-28 16:46 raymondoyondi Bug heat 0 => 2