HomePhorge

Defuse XSS in Calendar

Description

Defuse XSS in Calendar

Summary: addDetail() takes HTML because we have links there fairly often. :/ This design is iffy.

Test Plan: Reloaded /calendar/status/, verified no XSS.

Reviewers: btrahan, vrana

Reviewed By: vrana

CC: aran

Maniphest Tasks: T139

Differential Revision: https://secure.phabricator.com/D4074

Details

Provenance
epriestleyAuthored on Dec 3 2012, 4:46 PM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rP27785c4f759f: Don't delete tasks attached by freeform fields in Maniphest Tasks field
Branches
Unknown
Tags
Unknown

Event Timeline