New and Improved 3.13 Beta. Highlights: Shareable filters and dashboards and lots of other goodies. Any feedback can be raised as JIRA issues in the JIRA project.
Issue Details (XML | Word | Printable)

Key: CRUC-283
Type: Bug Bug
Status: Closed Closed
Resolution: Fixed
Priority: Major Major
Assignee: Joe Xie [atlassian]
Reporter: Matt Ryall [Atlassian]
Votes: 0
Watchers: 0
Operations

If you were logged in you would be able to see more operations.
Crucible

Escape HTML in Javascript properly

Created: 13/Mar/08 06:03 PM   Updated: 08/Apr/08 03:00 AM
Component/s: User Interface
Affects Version/s: 1.2.3
Fix Version/s: 1.5

Time Tracking:
Not Specified

File Attachments: None
Image Attachments:

1. Picture 4.png
(67 kB)

Participants: Joe Xie [atlassian] and Matt Ryall [Atlassian]
Since last comment: 23 weeks, 6 days ago
Resolution Date: 08/Apr/08 02:59 AM
Labels:


 Description  « Hide
You don't seem to escape stuff like "</script>" properly in your Javascript. It creates problems like in the top comments on this review:

https://svn.atlassian.com/privateeye/cru/CR-581

See attached screenshot.



 All   Comments   Work Log   Change History      Sort Order: Ascending order - Click to sort in descending order
Matt Ryall [Atlassian] added a comment - 13/Mar/08 06:04 PM
P.S. Don't use inline scripts.