#607 Sanitize HTML

v1.0.0
closed
nobody
sf-4 (350)
General
nobody
2015-08-20
2010-07-07
Anonymous
No

Originally created by: sf-overlords

Created by: rcopeland
Created date: 2010-06-17 21:23:09.531000
Assigned to:rcopeland

Currently we allow any HTML in markdown areas (wikis, comments, etc.), including \<script> tags. This should be fixed. See why? <script>alert('Users should not be able to do this!')</script>

Discussion

  • Anonymous - 2010-07-07

    Originally by: sf-overlords

    Post by mramm:

    • custom_field__size: --> 2
     
  • Anonymous - 2010-07-07

    Originally by: sf-overlords

    Post by rcopeland:

    description has changed

    • custom_field__size: -->

    • status: open --> validation

    • assigned_to: Rick Copeland

    • summary: Add HTML sanitization from the feedparser library --> Sanitize HTML

     

Log in to post a comment.