Over-escaped HTML entities in feed collection pages

RESOLVED FIXED

Status

Marketplace
Consumer Pages
P3
normal
RESOLVED FIXED
4 years ago
3 years ago

People

(Reporter: cvan, Assigned: spasovski)

Tracking

({regression})

regression
Points:
---

Details

(Whiteboard: [ktlo], URL)

(Reporter)

Description

4 years ago
1. Load homepage on -dev: https://marketplace-dev.allizom.org

2. Notice the collection title + description:

>    this is a mega collection"><script>alert('FART')</script><"
>    "><script>alert('FART')</script><"

https://www.dropbox.com/s/xb2jmh5cfv420p0/Screenshot%202014-11-03%2017.52.22.png?dl=0

3. Click the collection title to load its collection detail page: https://marketplace-dev.allizom.org/feed/collection/this-is-a-mega-collection?src=collection-element

4. Notice the title is fine, but the description is overescaped:

>    this is a mega collection"><script>alert('FART')</script><"
>    "&gt;&lt;script&gt;alert('FART')&lt;/script&gt;&lt;"

https://www.dropbox.com/s/rndgo91gm89ebc5/Screenshot%202014-11-03%2017.52.29.png?dl=0

Updated

4 years ago
Duplicate of this bug: 1131686

Updated

4 years ago
Assignee: nobody → dspasovski

Updated

4 years ago
Blocks: 1103195
(Assignee)

Comment 2

4 years ago
https://github.com/mozilla/fireplace/pull/1017
Status: NEW → RESOLVED
Last Resolved: 4 years ago
Resolution: --- → FIXED
Whiteboard: [ktlo]
Duplicate of this bug: 1166513
Status: RESOLVED → REOPENED
Keywords: regression
Resolution: FIXED → ---

Comment 4

3 years ago
Probably fixed by now.
Status: REOPENED → RESOLVED
Last Resolved: 4 years ago3 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.