Skip to content

[18.09] backport xss#7626

Merged
nsoranzo merged 4 commits intogalaxyproject:release_18.09from
martenson:18.09.backport-xss
Apr 1, 2019
Merged

[18.09] backport xss#7626
nsoranzo merged 4 commits intogalaxyproject:release_18.09from
martenson:18.09.backport-xss

Conversation

@martenson
Copy link
Member

@martenson martenson commented Mar 29, 2019

Backport of sanity-PR #7616 .

martenson and others added 3 commits March 29, 2019 14:15
which will not strip safe HTML tags and attributes, which we use.

Also, restrict the possible values of `status` instead of trying to
escape it.
@nsoranzo nsoranzo added this to the 18.09 milestone Mar 29, 2019
@martenson
Copy link
Member Author

the selenium fails are relevant here, I will push a fix

and expand to the messageLarge method
@martenson martenson force-pushed the 18.09.backport-xss branch from be1a36f to a07c99d Compare April 1, 2019 15:31
@nsoranzo nsoranzo merged commit d20cbad into galaxyproject:release_18.09 Apr 1, 2019
@nsoranzo nsoranzo deleted the 18.09.backport-xss branch April 1, 2019 17:04
@nsoranzo
Copy link
Member

nsoranzo commented Apr 1, 2019

Thanks @martenson !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants