Homestyx hydra
Diffusion hydra 02e8a322dc58

Defuse XSS in Calendar

Description

Defuse XSS in Calendar

Summary: addDetail() takes HTML because we have links there fairly often. :/ This design is iffy.

Test Plan: Reloaded /calendar/status/, verified no XSS.

Reviewers: btrahan, vrana

Reviewed By: vrana

CC: aran

Maniphest Tasks: T139

Differential Revision: https://secure.phabricator.com/D4074

Details

Provenance
epriestleyAuthored on Dec 3 2012, 7:46 PM
sirocylPushed on Oct 16 2024, 5:49 AM
Parents
R1:27785c4f759f: Don't delete tasks attached by freeform fields in Maniphest Tasks field
Branches
Unknown
Tags
Unknown

Event Timeline