CSS: notice images no wider than 100%

We should actually not allow remote images to be given in the src attribute
because they can be used for tracking and other nasty stuff without being
seen by the enduser.

Also, allowing remote images linked like this won't work for users who run
plugins like RequestPolicy etc. anyway. A better method would be to make
them listed as attachments instead. Then we can use that subsystem for
making thumbnails to store locally, hotlinking sources and whatnot.
This commit is contained in:
Mikael Nordfeldth 2015-02-17 01:26:18 +01:00
parent 6862184956
commit 406b6148f5
1 changed files with 4 additions and 0 deletions

View File

@ -713,6 +713,10 @@ font-style:italic;
overflow-y: auto;
}
.notice .e-content img {
max-width: 100%;
}
.notice-options {
margin-bottom: 7px;
margin-top: 12px;