Project

General

Profile

Actions

Defect #44586

open

Quoted attribute values are broken in HTML tags added to RedCloth3::ALLOWED_TAGS

Added by Go MAEDA about 12 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Text formatting
Resolution:
Affected version:

Description

When a tag is added to RedCloth3::ALLOWED_TAGS, attributes with quoted values do not work in Textile. For example, with font added to the list:

<font color="red">text</font>

is rendered as:

<font color="&quot;red&quot;">text</font>

Unquoted values such as <font color=red> work as expected.

This has been the case since r22302 (#38807). To prevent attribute injection, RedCloth3#escape_html_tags escapes the entire content of the allowed tags, including the quotes around attribute values.

The attached patch stops escaping the content of the allowed tags. It depends on #44585, which sanitizes the output of the Textile formatter. With the sanitizer in place, the escaping is no longer necessary: event handler attributes, links with an unsafe scheme, and arbitrary classes and ids are removed. Tags that are not listed in ALLOWED_TAGS are still escaped as before.


Files


Related issues

Blocked by Redmine - Feature #44585: Sanitize the HTML generated by the Textile formatter in the same way as the CommonMark formatterNewActions
Actions #1

Updated by Go MAEDA about 12 hours ago

  • Blocked by Feature #44585: Sanitize the HTML generated by the Textile formatter in the same way as the CommonMark formatter added
Actions

Also available in: Atom PDF