We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38783
    • 571 Posts
    I am using Login.UpdateProfile to allow front end users to edit their profiles.

    I would like to allow them to enter specific html tags in some fields, but I am having problems with this.

    Using the following users can enter html tags into the comment field.

    [[!UpdateProfile?
    &validate=`comment:allowTags`]]


    However I would like to be able to limit what tags they can use and thought the following would work, but it does not.

    [[!UpdateProfile?
    &validate=`comment:stripTags=^strong^`]]


    Any attempt to move the validation to the html of the form itself does not seem to work. ie:

    <label for="comment">[[!%login.comment]]
                <span class="error">[[+error.comment]]</span>
            </label>
            <input type="textarea" name="comment" id="comment" value="[[+comment:stripTags=`strong`]]" />


    I am obviously doing something wrong, but can't figure out what! Any help would be appreciated.

    This question has been answered by BobRay. See the first response.

      If I help you out on these forums I would be very grateful if you would consider rating me on Trustpilot: https://uk.trustpilot.com/review/andytough.com

      email: [email protected] | website: https://andytough.com
    • discuss.answer
      • 3749
      • 24,544 Posts
      I think you're confusing UpdateProfile validators with MODX output filters. AFAIK, there is no stripTags validator in UpdateProfile (I could be wrong).

      There is a stripTags output modifier, but it only acts when the page is rendered and would have no effect on a form's input field.

      The only way I can think of to do what you want is some fairly complex JavaScript that checks specific fields for disallowed HTML tags and prevents the form from submitting if they are there.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 38783
        • 571 Posts
        Thanks Bob.

        I that case I'll start by telling them that I won't be giving them access to any html tags and see how they react!
          If I help you out on these forums I would be very grateful if you would consider rating me on Trustpilot: https://uk.trustpilot.com/review/andytough.com

          email: [email protected] | website: https://andytough.com
          • 3749
          • 24,544 Posts
          Or just let them use any tags they want. Most client-users don't know any beyond p, b, and maybe i. wink
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 38783
            • 571 Posts
            Yes, that's true. And they are logged in users, who are members of the organisation, so they are not going to fill it up with spammy links. I think I was forgetting that it is not a publicly accessible form.
              If I help you out on these forums I would be very grateful if you would consider rating me on Trustpilot: https://uk.trustpilot.com/review/andytough.com

              email: [email protected] | website: https://andytough.com