This project is archived and is in readonly mode.
WhiteListSanitizer removes unknown tags instead of escaping.
-
antonmos
This changeset fixes the issue.
Some tests explicitly asserted that 'form' and 'plaintext' tags should be removed, thus I added them to the bad_tags list.
test_should_sanitize_tag_broken_up_by_null and test_should_sanitize_script_tag_with_multiple_open_brackets relied on removing unknown tags, but the new behavior should prevent script execution as well.
-
josh
- Tag changed from 2.0-stable, 2.1, sanitize to 2.0-stable, 2.1, patch, sanitize
- State changed from new to resolved
-
David Eisinger
- Tag cleared.
This is still broken:
http://github.com/rails/rails/blob/master/actionpack/lib/action_con...