Project

General

Profile

Actions

Defect #807

closed

HTML not escaped in ticket descriptions

Added by David Förster about 16 years ago. Updated about 16 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
UI
Target version:
-
Start date:
2008-03-07
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

HTML Tags are not escaped in ticket comments.


Related issues

Related to Redmine - Feature #20497: Markdown formatting supporting HTMLClosed

Actions
Related to Redmine - Feature #23717: Allow HTML View in description diffClosed

Actions
Actions #1

Updated by Rocco Stanzione about 16 years ago

I think this is a have-your-cake-and-eat-it-too scenario. Issue descriptions are textilized so they can be formatted, and part of that is accepting HTML as-is. You should probably put any HTML in the descriptions (that you don't want interpreted by browsers) into a

 tag.

Actions #2

Updated by Jean-Philippe Lang about 16 years ago

Actually, HTML is escaped here on redmine.org (eg. <h1>Redmine</h1>) except pre tags used for preformatted text.
I'll commit this change.

Actions #3

Updated by Jean-Philippe Lang about 16 years ago

  • Status changed from New to Closed
  • Resolution set to Fixed

Fixed in r1216 (only pre tags are not escaped).

Actions #4

Updated by Go MAEDA over 8 years ago

  • Related to Feature #20497: Markdown formatting supporting HTML added
Actions #5

Updated by Go MAEDA over 4 years ago

  • Related to Feature #23717: Allow HTML View in description diff added
Actions

Also available in: Atom PDF