Closed Bug 348308 Opened 18 years ago Closed 18 years ago

Email approval/denial comment is escaped for SQL

Categories

(addons.mozilla.org Graveyard :: Developer Pages, defect)

defect
Not set
minor

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: fligtar, Assigned: fligtar)

References

Details

Attachments

(1 file)

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.6) Gecko/20060728 Firefox/1.5.0.6
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.6) Gecko/20060728 Firefox/1.5.0.6

The comment sent in the email is escaped for SQL, making quotes coverted to htmlentities and single quotes escaped.

Reproducible: Always

Actual Results:  
Test Example:

Welcome to the Internet! 1.0 - Approval Granted
Your item, Welcome to the Internet! 1.0, has been reviewed by a Mozilla Update editor who took the following action:
Approval Granted

Please Note: It may take up to 30 minutes for your extension to be available for download.

Your item was tested by Justin Scott using Firefox 1.5-2.0a1 on BSD, Linux, MacOSX, Solaris, Windows.
Editor's Comments:
 I\'m sorry, but I\'m denying your extension because it needs uncommon external software in order to work, and as we don\'t have access to this software we are not likely to be able to review it any time soon. It has been in the queue for some time now, and I thought it would be bad to leave you without feedback any longer.
----
Mozilla Update: https://update-staging.mozilla.org/~fligtar/v1-approval/
Attached patch patchSplinter Review
What do you know, I already have a patch made for it!
Assignee: nobody → fligtar
Status: NEW → ASSIGNED
Attachment #233201 - Flags: first-review?(morgamic)
*** Bug 295114 has been marked as a duplicate of this bug. ***
Attachment #233201 - Flags: first-review?(morgamic) → first-review+
Committed.  Thanks, Justin -- you are t3h aw3s0m3.
Status: ASSIGNED → RESOLVED
Closed: 18 years ago
Resolution: --- → FIXED
Anything between < and >, and the "\" character is still stripped, but this is a definite improvement.
Status: RESOLVED → VERIFIED
OS: Windows XP → All
Hardware: PC → All
Version: unspecified → 1.0
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: