Menu du compte de l'utilisateur

  • Log in

Navigation principale

  • Home Page
  • All CMS
  • Tutorials
  • White Paper
Home
Guide CMS

Breadcrumb

  • Home
  • Tutorials
  • Drupal User Guide
  • Chapter 6. Setting Up Content Structure
  • 6.15. Concept: Text Formats and Editors

Language selector

  • Français
  • English

Main navigation

  • Home Page
  • All CMS
  • Tutorials
  • White Paper

User login

CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
  • Create new account
  • Reset your password

Book navigation

  • Tutorials
    • Drupal User Guide
      • Preface
      • Chapter 1. Understanding Drupal
      • Chapter 2. Planning Your Site
      • Chapter 3. Installation
      • Chapter 4. Basic Site Configuration
      • Chapter 5. Basic Page Management
      • Chapter 6. Setting Up Content Structure
        • 6.1. Adding a Content Type
        • 6.2. Deleting a Content Type
        • 6.3. Adding Basic Fields to a Content Type
        • 6.4. Concept: Reference Fields
        • 6.5. Concept: Taxonomy
        • 6.6. Setting Up a Taxonomy
        • 6.7. Adding a Reference Field
        • 6.8. Concept: Forms and Widgets
        • 6.9. Changing Content Entry Forms
        • 6.10. Concept: View Modes and Formatters
        • 6.11. Changing Content Display
        • 6.12. Concept: Image Styles
        • 6.13. Setting Up an Image Style
        • 6.14. Concept: Responsive Image Styles
        • 6.15. Concept: Text Formats and Editors
        • 6.16. Configuring Text Formats and Editors
      • Chapter 7. Managing User Accounts
      • Chapter 8. Blocks
      • Chapter 9. Creating Listings with Views

Guy Vigneault

6.15. Concept: Text Formats and Editors

By Guy Vigneault | 11:25 PM EDT, Thu March 12, 2026

What are text formats and filters?

Text formats change how HTML tags and other text are processed and displayed on your site. Text formats are composed of a series of filters, each of which transforms text. When users create content, a text format is associated with the content, and the full, original text is stored in the database. The content is then passed through the filters in the text format before it becomes output on the site.

The core Filter module provides text format functionality, and the core Standard installation profile sets up Basic HTML, Restricted HTML, and Full HTML text formats. Each text format has an associated permission, so that you can allow only trusted users to use permissive text formats. This restricts untrusted users to text formats like Basic HTML, which filters out dangerous HTML tags.

What are the editors associated with text formats?

Each text format can be associated with an editor, such as a visual WYSIWYG (What You See Is What You Get) HTML editor. The core Text Editor module provides the ability to associate editors with text formats, and to configure the editors (such as adding and removing buttons from their toolbars). The core CKEditor module provides the industry-standard editor known as CKEditor, so that it can be used to edit HTML content on your site.

What is cross-site scripting?

Cross-site scripting (XSS) is a security vulnerability typically found in websites. In a site that is not well protected, malicious users can enter script into web pages that are viewed by other users (for example, in a comment or in the body of a page). A cross-site scripting vulnerability may be used by attackers to login as another user. It is important to configure the text formats of your website to prevent such abuse.

Related topics

Section 13.3, “Concept: Security and Regular Updates”

Additional resources

  • Drupal.org community documentation page "Filter module overview"
  • Wikipedia page "Cross-site scripting"

Attributions

Written and edited by Boris Doesborg and Jennifer Hodgdon.

 

Book traversal links for Tutorials

  • ‹ 6.14. Concept: Responsive Image Styles
  • Up
  • 6.16. Configuring Text Formats and Editors ›
CMS

 

All CMS

 

Tuto

 

Tutorials

 

White Paper

 

White Paper

Powered by Drupal

Privacy Policy

Privacy Policy

 

Recent content

  • 9.3. Creating a Content List View
    5 days 7 hours ago
  • 9.2. Concept: The Parts of a View
    5 days 7 hours ago
  • 9.1. Concept: Uses of Views
    5 days 7 hours ago
  • Chapter 9. Creating Listings with Views
    5 days 7 hours ago
  • 8.3. Placing a Block in a Region
    1 month 2 weeks ago

Copyright

Creative Commons

Sauf mention contraire, Guide CMS © 2025 par Guy Vigneault est sous licence Creative Commons Attribution - Utilisation non commerciale - Partage dans les mêmes conditions 4.0 International

 

Creative Commons

Unless otherwise stated, Guide CMS © 2025 by Guy Vigneault is licensed under Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International Public License

eGV Web