Edgewall Software
Modify

Ticket #778 (closed defect: fixed)

Opened 8 years ago

Last modified 8 years ago

Logged in username not escaped

Reported by: Mark Rowe <bdash@…> Owned by: cmlenz
Priority: lowest Milestone: 0.8
Component: general Version: devel
Severity: trivial Keywords:
Cc:
Release Notes:
API Changes:

Description

When a user is logged in with a username that contains HTML characters such as "<" and ">", they are not correctly escaped when the username is displayed above the navigation in the text "Logged in as username".

Attachments

Change History

comment:1 Changed 8 years ago by daniel

  • Milestone set to 0.8
  • Priority changed from normal to lowest
  • Severity changed from normal to trivial

comment:2 Changed 8 years ago by cmlenz

  • Owner changed from jonas to cmlenz
  • Status changed from new to assigned
  • Summary changed from HTML Entities not escaped in logged in username to Logged in username not escaped

comment:3 Changed 8 years ago by cmlenz

  • Resolution set to fixed
  • Status changed from assigned to closed

Fixed in [958].

View

Add a comment

Modify Ticket

Change Properties
<Author field>
Action
as closed
The resolution will be deleted. Next status will be 'reopened'
to The owner will be changed from cmlenz. Next status will be 'closed'
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.