Actions
Bug #2622
closedNew Proxy dialog renders full HTML on error
Description
If you insert e.g. http://www.redhat.com:80 then the HTML is rendered. We should:
- only show first few lines of the output
- escape HTML entities there
I am testing more pages where we require an URL.
Low security impact.
Updated by Dominic Cleal over 11 years ago
The other aspect of this is proxy responses are likely used verbatim in success/failure popups etc, I know HTTP response messages certainly appear there.
Updated by Lukas Zapletal over 11 years ago
Right, created a task on backlog for this. There is much more :-(
Updated by Dominic Cleal over 11 years ago
- Status changed from Assigned to Ready For Testing
Updated by Lukas Zapletal over 11 years ago
- Status changed from Ready For Testing to Closed
- % Done changed from 0 to 100
Applied in changeset c8d1c6d713cc412bc4ab30b74e60e2ff98d8b74a.
Updated by Dominic Cleal over 11 years ago
- Status changed from Closed to Assigned
- % Done changed from 100 to 50
Sorry, accidentally pushed this. Please see my last comment in the PR and send a new PR for the additional change(s). Thanks!
Updated by Lukas Zapletal over 11 years ago
- Status changed from Assigned to Closed
- % Done changed from 50 to 100
Applied in changeset e80307751812093e70b9c0de7b566c04ef9a9712.
Actions