Closed Bug 955311 Opened 7 years ago Closed 7 years ago

Warn when receiving script and style tags in IM messages

Categories

(Chat Core :: General, enhancement)

enhancement
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Mic, Assigned: florian)

References

Details

Attachments

(1 file)

*** Original post on bio 1878 at 2013-02-19 14:41:00 UTC ***

When a received message contains a script or style tag, we could log a warning to the error console that dubious content was found. In my opinion that's better than silently filtering it out and let the (potential) attempt to tamper with the client go unnoticed.
Attached patch PatchSplinter Review
*** Original post on bio 1878 as attmnt 2239 at 2013-02-19 23:31:00 UTC was without comment, so any subsequent comment numbers will be shifted ***
Attachment #8354002 - Flags: review?(clokep)
Assignee: nobody → florian
Comment on attachment 8354002 [details] [diff] [review]
Patch

*** Original change on bio 1878 attmnt 2239 at 2013-02-19 23:33:03 UTC ***

Looks good!
Attachment #8354002 - Flags: review?(clokep) → review+
Blocks: 955303
*** Original post on bio 1878 at 2013-02-19 23:49:02 UTC ***

Thanks for fixing this so fast flo!

http://hg.instantbird.org/instantbird/rev/e8c8d59028ac
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
Target Milestone: --- → 1.4
You need to log in before you can comment on or make changes to this bug.