Homec4science

Defuse XSS in Calendar

Authored by epriestley <git@epriestley.com> on Dec 4 2012, 01:46.

Description

Defuse XSS in Calendar

Summary: addDetail() takes HTML because we have links there fairly often. :/ This design is iffy.

Test Plan: Reloaded /calendar/status/, verified no XSS.

Reviewers: btrahan, vrana

Reviewed By: vrana

CC: aran

Maniphest Tasks: T139

Differential Revision: https://secure.phabricator.com/D4074

Details

Committed
epriestley <git@epriestley.com>Dec 4 2012, 01:46
Pushed
aubortJan 31 2017, 17:16
Parents
rPH27785c4f759f: Don't delete tasks attached by freeform fields in Maniphest Tasks field
Branches
Unknown
Tags
Unknown

Event Timeline

epriestley <git@epriestley.com> committed rPH02e8a322dc58: Defuse XSS in Calendar (authored by epriestley <git@epriestley.com>).Dec 4 2012, 01:46