-
Notifications
You must be signed in to change notification settings - Fork 167
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sanitize file name #851
Sanitize file name #851
Conversation
Can one of the admins verify this patch? |
Disclaimer: I have no idea how to run the tests and don't feel very keen to install Qt and Co. for that on my machine. So if you want that function tested it would be appreciated if you could come up with one instead of having me digging into that too ;-) |
ok to test |
Build succeeded. |
Related previous discussion about encoding: #783 (comment)
Installing Qt5 (at least what is needed for QWebKit) should be sufficient to get the test running automatically. Not much Co. should be coinstalled by that. Ask your package manager. Then, you can also run the tests manually using your browser though:
then navigate your browser(s) to http://127.0.0.1:8124/tests/tests.html You could also use a custom webserver, but some tests expect to be able to save files by PUT requests, so they would fail with other webservers that do not do the expected PUT handling. Task for me: add note about httpserver.js to webodf/tests/README |
|
||
// FIXME: We need to support parametrized strings, because | ||
// drop-in word replacements are inadequate for translations; | ||
// see http://techbase.kde.org/Development/Tutorials/Localization/i18n_Mistakes#Pitfall_.232:_Word_Puzzles | ||
element.innerHTML = runtime.tr('Loading') + ' ' + url + '...'; | ||
element.innerHTML = runtime.tr('Loading') + ' ' + utils.escapeHtml(url) + '...'; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There is actually an easier way to do this that avoids any manual HTML escaping:
element.innerHTML = "";
element.appendChild(element.ownerDocument.createTextNode(runtime.tr('Loading') + url + '...'));
That would be my preference here
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fair point. Will adjust. My Javascript clean-code ability are somewhat suboptimal ;-)
Otherwise a DOM-based XSS is possible.
e5ba77f
to
9d170f8
Compare
@peitschie Incorporated your suggestions. THX for review. Care to take a second look? :-) |
Build succeeded. |
This patch looks good to me. Just needs @kossebau approval now 😄 |
Fine with me as well. Thanks for the patch, merging (so your patch now opening the 2015 commit/merge series :) ). |
Another bunch…