diff --git a/main/inc/lib/security.lib.php b/main/inc/lib/security.lib.php index 5623e85fb4..9dcc4d9ab0 100644 --- a/main/inc/lib/security.lib.php +++ b/main/inc/lib/security.lib.php @@ -346,6 +346,18 @@ class Security $config->set('CSS.AllowImportant', true); $config->set('CSS.AllowTricky', true); // We need for the flv player the css definition display: none; $config->set('CSS.Proprietary', true); + + // Allow uri scheme. + $config->set('URI.AllowedSchemes', array( + 'http' => true, + 'https' => true, + 'mailto' => true, + 'ftp' => true, + 'nntp' => true, + 'news' => true, + 'data' => true, + )); + $purifier[$user_status] = new HTMLPurifier($config); }