[Sakai Jira] Commented: (SAKIII-2006) Values entered in the contentmetadata widget should be escaped

Nicolaas Matthijs (JIRA) sakai-ui-dev-tracking at collab.sakaiproject.org
Thu Jan 27 03:02:59 PST 2011


    [ https://jira.sakaiproject.org/browse/SAKIII-2006?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=118369#comment-118369 ] 

Nicolaas Matthijs commented on SAKIII-2006:
-------------------------------------------

Fix verified. Will merge in soon.

> Values entered in the contentmetadata widget should be escaped
> --------------------------------------------------------------
>
>                 Key: SAKIII-2006
>                 URL: https://jira.sakaiproject.org/browse/SAKIII-2006
>             Project: Sakai 3 UI Dev
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: Sprint 101: Backlog 1
>            Reporter: Nicolaas Matthijs
>            Assignee: Bert Pareyn
>            Priority: Critical
>             Fix For: Sprint 103: Stabilization and QA
>
>         Attachments: Picture 49.png, Picture 50.png, Picture 57.png
>
>
> Values entered in the contentmetadata widget should be escaped. Right now, I can just enter HTML and it will be rendered.

-- 
This message is automatically generated by JIRA.
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


More information about the sakai-ui-dev-tracking mailing list