Html in PR comments not encoded

XMLWordPrintable

      I wrote this comment:

      This will be very hard to read in the javadoc. Add <br>s or <li>s or at least semi-colons between lines.
      

      The html wasn't escaped and is parsed by the browser. Not cool. I can't comment or edit comments any more on the PR, and if I weren't really busy I'd be hunting for XSS attacks.

      https://stash.atlassian.com/projects/CONF/repos/confluence/pull-requests/1331/overview?commentId=9508 is the review in question

            Assignee:
            jhinch (Atlassian)
            Reporter:
            Don Willis
            Votes:
            0 Vote for this issue
            Watchers:
            10 Start watching this issue

              Created:
              Updated:
              Resolved: