Defect #44586
openQuoted attribute values are broken in HTML tags added to RedCloth3::ALLOWED_TAGS
Description
When a tag is added to RedCloth3::ALLOWED_TAGS, attributes with quoted values do not work in Textile. For example, with font added to the list:
<font color="red">text</font>
is rendered as:
<font color=""red"">text</font>
Unquoted values such as <font color=red> work as expected.
This has been the case since r22302 (#38807). To prevent attribute injection, RedCloth3#escape_html_tags escapes the entire content of the allowed tags, including the quotes around attribute values.
The attached patch stops escaping the content of the allowed tags. It depends on #44585, which sanitizes the output of the Textile formatter. With the sanitizer in place, the escaping is no longer necessary: event handler attributes, links with an unsafe scheme, and arbitrary classes and ids are removed. Tags that are not listed in ALLOWED_TAGS are still escaped as before.
Files
Related issues
Updated by Go MAEDA about 13 hours ago
- Blocked by Feature #44585: Sanitize the HTML generated by the Textile formatter in the same way as the CommonMark formatter added