Allowed Content Reference

The exact set of HTML tags, attributes, inline styles, classes, and URL schemes the forum's sanitizer keeps when you save a post. Anything not listed here is removed on save.  ·  Back to the forum

Generated 2026-09-06T19:38:16.015Z from the server sanitizer (the security authority).

The Rich-Text editor column shows what happens to each construct if you switch a post from HTML mode into the visual editor and back. Most content survives; the markers below flag the exceptions.

✓ keeps survives unchanged · ↻ normalizes to CSS kept, rewritten as CSS · ↑ upgrades to native legacy form, becomes the native equivalent · 🔒 blocked (security) removed by the sanitizer regardless of mode · ✗ HTML mode only not represented in the visual editor — author it in HTML mode

Contents

Tags & attributes Inline styles CSS classes URL schemes

Tags & attributes

Each allowed tag and the attributes it may carry. Inline style values are governed by the Inline styles section; class values by the CSS classes section.

TagAllowed attributesURL schemesRich-Text editor
<a>hreftargetrelstyleclassdata-typedata-page-iddata-page-slugdata-page-existsdata-game-slug(default)✓ keeps
<b>classstyle(default)✓ keeps
<blockquote>classstyledata-authordata-author-iddata-post-iddata-timestampdata-hydrateddata-ipsquote-timestampdata-ipsquote-useriddata-ipsquote-usernamedata-ipsquote-contentappdata-ipsquote-contenttypedata-ipsquote-contentiddata-ipsquote-contentclassdata-ipsquote-contentcommentid(default)✓ keeps
<br>classstyle(default)✓ keeps
<code>class(default)✓ keeps
<col>stylespanwidthalign(default)✓ keeps
<colgroup>spanwidthalign(default)✓ keeps
<del>classstyle(default)✓ keeps
<div>classstyletitledata-authordata-author-iddata-post-iddata-timestampdata-modedata-recipientsdata-aligndata-margindata-padding(default)✓ keeps
<em>classstyle(default)✓ keeps
<fieldset>classstyle(default)✓ keeps
<h1>style(default)✓ keeps
<h2>style(default)✓ keeps
<h3>style(default)✓ keeps
<h4>style(default)✓ keeps
<h5>style(default)✓ keeps
<h6>style(default)✓ keeps
<hr>classstyle(default)✓ keeps
<i>classstyle(default)✓ keeps
<img>srcalttitlewidthheightclassstyledata-spacingdata-emojiloadinghttps, data✓ keeps
<legend>classstyledata-title-html(default)✓ keeps
<li>stylevalue(default)✓ keeps
<mark>classstyle(default)✓ keeps
<ol>stylestart(default)✓ keeps
<p>style(default)✓ keeps
<pre>classstyle(default)✓ keeps
<s>classstyle(default)✓ keeps
<span>classstyletitledata-typedata-iddata-labeldata-showndata-hiddendata-languagedata-inline-dicedata-roll-set-iddata-display-modedata-dice-refdata-dice-strikedata-tpl-placeholderdata-canonical-pathdata-field-keydata-template-keydata-original-valuedata-sheet-id(default)✓ keeps
<strong>classstyle(default)✓ keeps
<sub>classstyle(default)✓ keeps
<sup>classstyle(default)✓ keeps
<table>classstylewidthcellpaddingcellspacingborderalignbgcolordata-zebra(default)✓ keeps
<tbody>classstylealignvalignbgcolor(default)✓ keeps
<td>colspanrowspanstylecolwidthwidthheightalignvalignbgcolornowrap(default)✓ keeps
<tfoot>classstylealignvalignbgcolor(default)✗ HTML mode only
<th>colspanrowspanscopestylecolwidthwidthheightalignvalignbgcolornowrap(default)✓ keeps
<thead>classstylealignvalignbgcolor(default)✗ HTML mode only
<tr>stylealignvalignbgcolor(default)✓ keeps
<u>classstyle(default)✓ keeps
<ul>style(default)✓ keeps

Inline styles

CSS properties accepted in a style="…" attribute on any element, with the value shapes the server allows. Values that don't match are dropped. The Rich-Text editor column shows whether the property survives a switch on a block element and/or on an inline <span>.

Text Styling

PropertyAccepted valuesRich-Text editor
colorhex color (3, 4, 6, or 8 digits); rgb() color; rgba() color (with alpha); a named color (e.g. red, navy); a theme palette color, rgb(var(--mwpalette-…))✓ block & inline
text-alignleft; right; center; justify; start; -webkit-left✓ block & inline
font-sizea font-size keyword, or a number with px/em/rem/%/pt✓ block & inline
font-familya font-family name or stack✓ block & inline
font-weightnormal, bold, bolder, lighter, or a 3-digit weight✓ block & inline
font-styleone of: normal, italic, oblique✓ block & inline
text-decorationany value✓ block & inline
text-decoration-stylea line style: solid, double, dotted, dashed, or wavy✓ block & inline
text-decoration-thicknessany value✓ block & inline
text-decoration-lineany value✓ block & inline
line-heightnormal, or a number with %/px/em/rem✓ block & inline
letter-spacingnormal, or a number (may be negative) with px/em/rem✓ block & inline
word-spacingnormal, or a number (may be negative) with px/em/rem✓ block & inline
text-indenta number (may be negative) with px/em/rem/%✓ block & inline
text-transformone of: none, capitalize, uppercase, lowercase✓ block & inline
white-spaceone of: normal, nowrap, pre, pre-wrap, pre-line, break-spaces✓ block & inline
font-variantany value✓ block & inline
font-variant-ligaturesany value✓ block & inline
font-variant-capsany value✓ block & inline

Dimensions

PropertyAccepted valuesRich-Text editor
widtha positive number, optionally with px/%/em/rem✓ block & inline
min-widtha positive number with px/%/em/rem, optional !important✓ block & inline
max-widtha positive number, optionally with px/%/em/rem✓ block & inline
heightauto, or a positive number with px/%/em/rem✓ block & inline
min-heighta positive number, optionally with px/%/em/rem✓ block & inline
max-heighta positive number, optionally with px/%/em/rem✓ block & inline

Background

PropertyAccepted valuesRich-Text editor
background-colorhex color (3, 4, 6, or 8 digits); rgb() color; rgba() color (with alpha); a named color (e.g. red, navy); transparent; a theme palette color, rgb(var(--mwpalette-…))✓ block & inline
backgroundany value with no url() (e.g. a gradient); matches pattern ^url\(\s*(['"]?)https:\/\/(?:(?:[a-z0-9-]+\.)*myth-weavers\.com|(?:pbp-forum-uploads|mwbaldrcdkstack-ipbuploads[a-z0-9-]+)\.s3\.(?:[a-z0-9-]+\.)?amazonaws\.com)\/[^'"\s)]*\1\s*\)$✓ block & inline
background-imageany value with no url() (e.g. a gradient); matches pattern ^url\(\s*(['"]?)https:\/\/(?:(?:[a-z0-9-]+\.)*myth-weavers\.com|(?:pbp-forum-uploads|mwbaldrcdkstack-ipbuploads[a-z0-9-]+)\.s3\.(?:[a-z0-9-]+\.)?amazonaws\.com)\/[^'"\s)]*\1\s*\)$✓ block & inline
background-sizeany value✓ block & inline
background-positionany value✓ block & inline
background-repeata background-repeat value (one or two of repeat, repeat-x, repeat-y, no-repeat, space, round)✓ block & inline
background-attachmentone of: scroll, fixed, local✓ block & inline

Border

PropertyAccepted valuesRich-Text editor
borderany value✓ block & inline
border-topany value✓ block & inline
border-rightany value✓ block & inline
border-bottomany value✓ block & inline
border-leftany value✓ block & inline
border-styleone or more border styles (none, solid, dashed, dotted, inset, outset, ridge, groove, double, thin)✓ block & inline
border-widthone or more lengths with px/em/rem✓ block & inline
border-colorhex color (3, 4, 6, or 8 digits); rgb() color; rgba() color (with alpha); a named color (e.g. red, navy); a theme palette color, rgb(var(--mwpalette-…))✓ block & inline
border-radiusone or more lengths with px/em/rem/%✓ block & inline
border-collapseone of: collapse, separate✓ block & inline
border-spacingone or two lengths with px/em/rem✓ block & inline

Spacing

PropertyAccepted valuesRich-Text editor
paddingone or more lengths with px/em/rem/%/vh✓ block & inline
padding-topa non-negative number with px/em/rem/%✓ block & inline
padding-righta non-negative number with px/em/rem/%✓ block & inline
padding-bottoma non-negative number with px/em/rem/%✓ block & inline
padding-lefta non-negative number with px/em/rem/%✓ block & inline
marginmatches pattern ^(auto|-?[\d.]+(px|em|rem|%|pt|in|cm)?)(\s+(auto|-?[\d.]+(px|em|rem|%|pt|in|cm)?))*$✓ block & inline
margin-topa number (may be negative) with px/em/rem/%/pt/in/cm✓ block & inline
margin-rightmatches pattern ^(auto|-?[\d.]+(px|em|rem|%)?)$✓ block & inline
margin-bottoma number (may be negative) with px/em/rem/%/pt/in/cm✓ block & inline
margin-leftmatches pattern ^(auto|-?[\d.]+(px|em|rem|%)?)$✓ inline

Layout

PropertyAccepted valuesRich-Text editor
vertical-alignone of: top, middle, bottom, baseline, text-top, text-bottom, inherit✓ block & inline
displaymatches pattern ^(none|block|inline|inline-block|flow-root|list-item|inline-table|table|table-row|table-cell|table-caption|table-column|table-column-group|table-row-group|table-header-group|table-footer-group|flex|inline-flex|grid|inline-grid)(\s*!important)?$✓ block & inline
floatone of: none, left, right, center, unset✓ block & inline
clearone of: none, left, right, both✓ block & inline
overflowone of: visible, hidden, scroll, auto✓ block & inline
box-sizingone of: content-box, border-box✓ block & inline
flexany value✓ block & inline
flex-directionany value✓ block & inline
flex-wrapany value✓ block & inline
flex-flowany value✓ block & inline
flex-growany value✓ block & inline
flex-shrinkany value✓ block & inline
flex-basisany value✓ block & inline
align-itemsany value✓ block & inline
align-contentany value✓ block & inline
align-selfany value✓ block & inline
justify-contentany value✓ block & inline
justify-itemsany value✓ block & inline
justify-selfany value✓ block & inline
gapany value✓ block & inline
row-gapany value✓ block & inline
column-gapany value✓ block & inline
orderany value✓ block & inline
gridany value✓ block & inline
grid-templateany value✓ block & inline
grid-template-columnsany value✓ block & inline
grid-template-rowsany value✓ block & inline
grid-template-areasany value✗ HTML mode only
grid-columnany value✓ block & inline
grid-rowany value✓ block & inline
grid-areaany value✓ block & inline
grid-auto-columnsany value✓ block & inline
grid-auto-rowsany value✓ block & inline
grid-auto-flowany value✓ block & inline

Positioning

PropertyAccepted valuesRich-Text editor
positionone of: static, relative✓ block & inline
topa number (may be negative) with px/em/rem/%✓ block & inline
lefta number (may be negative) with px/em/rem/%✓ block & inline
righta number (may be negative) with px/em/rem/%✓ block & inline
bottoma number (may be negative) with px/em/rem/%✓ block & inline
z-indexan integer (may be negative)✓ block & inline

Visual

PropertyAccepted valuesRich-Text editor
opacitya number, optionally as a percentage✓ block & inline
outlineany value✓ block & inline
transformany value✓ block & inline
cursorone of: auto, default, pointer, text, move, not-allowed, crosshair, grab, grabbing, help, wait, progress, none, cell, context-menu, copy, alias, no-drop, zoom-in, zoom-out, n-resize, s-resize, e-resize, w-resize, nw-resize, ne-resize, sw-resize, se-resize, ew-resize, ns-resize, nesw-resize, nwse-resize, col-resize, row-resize, all-scroll, vertical-text✓ block & inline
box-shadowany value✓ block & inline
text-shadowany value✓ block & inline

Lists

PropertyAccepted valuesRich-Text editor
list-styleany value✓ block & inline
list-style-typeone of: none, disc, circle, square, decimal, lower-alpha, upper-alpha, lower-roman, upper-roman✓ block & inline

Other

PropertyAccepted valuesRich-Text editor
--table-border-widtha number, optionally with px✓ block & inline
--table-cell-paddinga number, optionally with px✓ block & inline
--table-margina number, optionally with px✓ block & inline

CSS classes

Class names accepted on any element. Entries shown with a trailing pattern (e.g. language-…) match any class with that prefix.

ProseMirror hljs-… code-block code-block-header editor-table hljs ipsAttachLink ipsAttachLink_center ipsAttachLink_image ipsAttachLink_left ipsAttachLink_right ipsCode ipsImage ipsImage_thumbnailed ipsQuote ipsQuote_citation ipsQuote_contents ipsSpoiler ipsSpoiler_contents ipsSpoiler_header ipsStyle_spoiler legacy-anchor legacy-attachment legacy-dice legacy-dice-formula legacy-dice-result legacy-dice-results legacy-dice-warning legacy-post-link legacy-thread-link mention mention-group mention-user mw-clear-float mw-emoji mw-fieldset mw-fieldset-body mw-fieldset-legend mw-float mw-float-border-thick mw-float-border-thin mw-float-left mw-float-right mw-language mw-private mw-private-body mw-private-hidden mw-private-shown mw-privatefrom mwbbcode mwbbcode-bb mwbbcode-html mwlang mwlang-content mwlang-label mwlang-obscured mwlang-unknown mwooc mwooc-hidden mwooc-shown mwprivate mwprivate-content mwprivate-header mwprivate-hidden-placeholder mwspoiler mwspoiler-hidden mwspoiler-hidetext mwspoiler-shown mwspoiler-showtext page-link page-link-new post-gm post-ic post-image post-image-center post-image-left post-image-link post-image-right post-ooc post-quote quote-attribution quote-content table-wrapper text-danger text-info text-muted text-success text-warning tpl-placeholder-chip tpl-placeholder-chip--dangling tpl-placeholder-chip--edited visibility-gm-only visibility-whisper

Rich-Text editor behavior

How these classes behave when a post is switched into the visual editor. Classes not listed here round-trip unchanged.

ClassOn switchWhat happens
ipsAttachLink_center↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsAttachLink_left↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsAttachLink_right↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsCode↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsQuote↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsQuote_citation↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsQuote_contents↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsSpoiler↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsSpoiler_contents↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsSpoiler_header↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
ipsStyle_spoiler↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
legacy-attachment↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
legacy-dice↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
legacy-dice-formula↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
legacy-dice-result↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
legacy-dice-results↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
legacy-dice-warning↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mw-language↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mw-private↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mw-private-body↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mw-private-hidden↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mw-private-shown↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mw-privatefrom↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mwbbcode↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mwbbcode-bb↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
mwbbcode-html↑ upgrades to nativeLegacy/imported form — the Rich-Text editor UPGRADES it to the native equivalent on switch (the legacy class/attribute is replaced by the native structure). No content is lost.
post-gm✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
post-ic✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
post-ooc✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
text-danger✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
text-info✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
text-muted✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
text-success✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
text-warning✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
visibility-gm-only✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.
visibility-whisper✗ HTML mode onlyBootstrap/post-type utility classes (text-muted, post-ic, visibility-*, …) on plain elements are dropped — the Rich-Text editor doesn't carry arbitrary CSS classes. The text survives unstyled. Apply styling via the toolbar, or keep it in HTML mode.

Tag-specific classes

TagClasses
<code>language-… lang-…
<pre>lang-…

URL schemes

Which URL schemes are accepted in link/image addresses.

Default (links and most elements): http, https

<img>: https, data

🔒 blocked (security) img: http — dropped by the sanitizer regardless of editor mode (phishing / mixed-content safety).