Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

WhiteListSanitizer removes unknown tags instead of escaping.

#916

Quoting the comment in santizier.rb for bad_tags member: "# Specifies a Set of 'bad' tags that the #sanitize helper will remove completely, as opposed to just escaping harmless tags like <font>"

However, the current code completely removes all unknown tags regardless of bad_tags set.

This is a problem because users may want to use text enclosed in < and > characters in their content (i.e. forum posts) and simply removing them is confusing and (unpleasantly) surprising.

Reported by antonmos · August 27th, 2008 @ 03:45 PM

State: resolved
Milestone: 2.x
Assigned to: nobody
Importance: none

Activity

  1. antonmos
    antonmos

    This changeset fixes the issue.

    Some tests explicitly asserted that 'form' and 'plaintext' tags should be removed, thus I added them to the bad_tags list.

    test_should_sanitize_tag_broken_up_by_null and test_should_sanitize_script_tag_with_multiple_open_brackets relied on removing unknown tags, but the new behavior should prevent script execution as well.

    August 27th, 2008 @ 04:23 PM

  2. josh
    josh
    • Tag changed from 2.0-stable, 2.1, sanitize to 2.0-stable, 2.1, patch, sanitize
    • State changed from new to resolved

    December 3rd, 2008 @ 03:25 PM

  3. David Eisinger
  4. bingbing