diff --git a/CTFd/admin/__init__.py b/CTFd/admin/__init__.py index 824f8314..3d6af66a 100644 --- a/CTFd/admin/__init__.py +++ b/CTFd/admin/__init__.py @@ -48,7 +48,7 @@ from CTFd.models import ( db, ) from CTFd.utils import config as ctf_config -from CTFd.utils import get_config, set_config +from CTFd.utils import get_app_config, get_config, set_config from CTFd.utils.csv import dump_csv, load_challenges_csv, load_teams_csv, load_users_csv from CTFd.utils.decorators import admins_only from CTFd.utils.exports import background_import_ctf @@ -190,7 +190,14 @@ def config(): except ValueError: pass - return render_template("admin/config.html", themes=themes, **configs) + force_html_sanitization = get_app_config("HTML_SANITIZATION") + + return render_template( + "admin/config.html", + themes=themes, + **configs, + force_html_sanitization=force_html_sanitization + ) @admin.route("/admin/reset", methods=["GET", "POST"]) diff --git a/CTFd/themes/admin/templates/configs/security.html b/CTFd/themes/admin/templates/configs/security.html index 387e4299..79a1f0a2 100644 --- a/CTFd/themes/admin/templates/configs/security.html +++ b/CTFd/themes/admin/templates/configs/security.html @@ -1,5 +1,28 @@
+ {% set html_sanitization = "true" if html_sanitization == True else "false" %}
+
+ + +