Closed Bug 1093420 Opened 6 years ago Closed 5 years ago

Over-escaped HTML entities in feed collection pages

Categories

(Marketplace Graveyard :: Consumer Pages, defect, P3)

defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: cvan, Assigned: spasovski)

References

()

Details

(Keywords: regression, Whiteboard: [ktlo])

1. Load homepage on -dev: https://marketplace-dev.allizom.org

2. Notice the collection title + description:

>    this is a mega collection"><script>alert('****')</script><"
>    "><script>alert('****')</script><"

https://www.dropbox.com/s/xb2jmh5cfv420p0/Screenshot%202014-11-03%2017.52.22.png?dl=0

3. Click the collection title to load its collection detail page: https://marketplace-dev.allizom.org/feed/collection/this-is-a-mega-collection?src=collection-element

4. Notice the title is fine, but the description is overescaped:

>    this is a mega collection"><script>alert('****')</script><"
>    "&gt;&lt;script&gt;alert('****')&lt;/script&gt;&lt;"

https://www.dropbox.com/s/rndgo91gm89ebc5/Screenshot%202014-11-03%2017.52.29.png?dl=0
Duplicate of this bug: 1131686
Assignee: nobody → dspasovski
Blocks: 1103195
https://github.com/mozilla/fireplace/pull/1017
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
See Also: → 1142301
Whiteboard: [ktlo]
Duplicate of this bug: 1166513
Status: RESOLVED → REOPENED
Keywords: regression
Resolution: FIXED → ---
Probably fixed by now.
Status: REOPENED → RESOLVED
Closed: 6 years ago5 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.