Skip to content

Conversation

@DanCech
Copy link
Member

@DanCech DanCech commented Jul 11, 2018

Ext.Msg.alert doesn't automatically escape HTML special characters in the message, which can lead to display issues and could be a potential area for XSS.

The new htmlEncode function added errs on the side of caution by encoding all characters other than alphanumeric and space.

@DanCech DanCech added this to the 1.2.0 milestone Jul 11, 2018
@DanCech DanCech self-assigned this Jul 11, 2018
@DanCech DanCech requested a review from cbowman0 July 11, 2018 15:53
@codecov-io
Copy link

codecov-io commented Jul 11, 2018

Codecov Report

Merging #2317 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master    #2317   +/-   ##
=======================================
  Coverage   79.62%   79.62%           
=======================================
  Files          85       85           
  Lines        8847     8847           
  Branches     1893     1893           
=======================================
  Hits         7044     7044           
  Misses       1544     1544           
  Partials      259      259

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 250742f...1e72eee. Read the comment docs.

@deniszh
Copy link
Member

deniszh commented Aug 19, 2018

@cbowman0 - could you please take a peek on this PR, please? Thanks a lot!

@DanCech DanCech merged commit 17e2e1f into graphite-project:master Sep 7, 2018
@DanCech DanCech deleted the htmlEncode branch September 7, 2018 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants