diff --git a/app/assets/javascripts/ckeditor/config.js b/app/assets/javascripts/ckeditor/config.js index c6dbd10da..305d0faf9 100644 --- a/app/assets/javascripts/ckeditor/config.js +++ b/app/assets/javascripts/ckeditor/config.js @@ -14,6 +14,7 @@ CKEDITOR.editorConfig = function( config ) config.filebrowserUploadUrl = "/ckeditor/attachment_files"; config.allowedContent = true; + config.format_tags = "p;h2;h3"; // Rails CSRF token config.filebrowserParams = function(){ diff --git a/lib/wysiwyg_sanitizer.rb b/lib/wysiwyg_sanitizer.rb index 64c26c34f..26792b21c 100644 --- a/lib/wysiwyg_sanitizer.rb +++ b/lib/wysiwyg_sanitizer.rb @@ -1,6 +1,6 @@ class WYSIWYGSanitizer - ALLOWED_TAGS = %w(p ul ol li strong em u s img a h1 h2 h3 h4 h6 pre addres div) + ALLOWED_TAGS = %w(p ul ol li strong em u s img a h2 h3) ALLOWED_ATTRIBUTES = %w(href style src alt) def sanitize(html)