What's going on with encoding?

What's going on with encoding? If I type (including the angle brackets), I get an empty item. I tried XSS but fortunately that doesn't work, at least not trivially. Why isn't everything HTML-encoded by default?

Comments

  1. Hello Thomas, Checkvist supports HTML by default, and tries to avoid XSS as much as possible. To be able to include tags and code unparsed, you can enable Markdown (if it is not enabled yet), and use Markdown syntax for code: https://checkvist.com/auth/help#markdown

    Hope, this helps.

    ReplyDelete
  2. Ahhh, it's the Markdown parser, of course. Thanks for enlightening me!

    ReplyDelete

Post a Comment

Popular posts from this blog

I'm really enjoy using checkvist, you are adding great features very quickly.

Hello friends

Hello friends!