You are here: Foswiki>Tasks Web>Item2495 (17 Jan 2010, PaulHarvey)Edit Attach

Item2495: OopsException documents false example using macros in parameters

pencil
Priority: Normal
Current State: Closed
Released In: 1.0.9
Target Release: patch
Applies To: Engine
Component:
Branches:
Reported By: KennethLavrsen
Waiting For:
Last Change By: PaulHarvey
In Foswiki::OopsException it is stated that we entity-encode parameters so protect against XSS.

But we also document an example where we pass on MAKETEXT. This is confusing for plugin authors.

Fixing the example and making the limitation clear.

-- KennethLavrsen - 11 Dec 2009

ItemTemplate edit

Summary OopsException documents false example using macros in parameters
ReportedBy KennethLavrsen
Codebase 1.0.8, trunk
SVN Range
AppliesTo Engine
Component
Priority Normal
CurrentState Closed
WaitingFor
Checkins distro:9ee38ee322a6 distro:942e1e29b55b
TargetRelease patch
ReleasedIn 1.0.9
Topic revision: r4 - 17 Jan 2010, PaulHarvey
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy