AUR web interface

Tasklist

FS#3315 - < is not escaped

Attached to Project: AUR web interface
Opened by Mircea Bardac (IceRAM) - Sunday, 09 October 2005, 08:33 GMT
Task Type Bug Report
Category Backend
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version 1.1
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No
This task depends upon

Closed by  Simo Leone (neotuli)
Thursday, 03 August 2006, 03:53 GMT
Reason for closing:  Won't fix
Additional comments about closing:  this is just the way php's strip_tags() works, and is only an issue if someone uses a less-than character (<) not followed by a space.
Unfortunately there's no way we can really separate <dangeroustag> from <justacomment, so I guess we have to live with it.
Comment by Simo Leone (neotuli) - Friday, 30 December 2005, 06:12 GMT
Sorry for the large delay, what is missing from that post? I believe we currently strip out quite a bit of that stuff.
Comment by Mircea Bardac (IceRAM) - Friday, 30 December 2005, 21:20 GMT
One of my comments there (IceRAM's) had a "<" somewhere around there, which is not rendered. Not really remember where.
You might be more lucky looking directly in the AUR database.
Comment by Douglas Soares de Andrade (dsa) - Saturday, 10 June 2006, 01:19 GMT
Closed ?
Comment by Mircea Bardac (IceRAM) - Saturday, 10 June 2006, 01:24 GMT
Hmm... I don't know.
I haven't posted a comment with "<" lately. If it's not reproductible when somebody tries this, then it's fixed.
Comment by Douglas Soares de Andrade (dsa) - Saturday, 10 June 2006, 01:26 GMT
Ok then :)
Comment by Paul Mattal (paul) - Wednesday, 02 August 2006, 05:22 GMT
Interesting; by themselves, < seem okay. For instance:

< foo >

is okay

but:

<foo>

is not

also okay:

>foo

<

bar>
Comment by Paul Mattal (paul) - Wednesday, 02 August 2006, 05:23 GMT
dsa, want to take a whack at this one?
Comment by Douglas Soares de Andrade (dsa) - Wednesday, 02 August 2006, 12:26 GMT
Of course, Paul. As soon as i kill it i will send the patch to you.

Loading...