-
Bug
-
Resolution: Timed out
-
Low
-
None
-
5.0.6, 5.1, 5.2
-
None
-
5
-
Severity 3 - Minor
-
-
This text implies that the workaround mode is only applied when the user's browser is MSIE. While part of the code that enforces it does indeed check the browser's user agent, JRA-20915 and JRA-28331 changed the enforcement of it such that the wiki renderer is instructed not to inline embedded objects at all, regardless of the browser setting, when in "workaround" mode.
Based on conversations with several people, this change in behaviour is entirely intentional, so we need to update the descriptions for this setting (as well as any related documentation) so it is clear what the enforcement does and that it applies to all browsers.
Actual behaviour in 5.0.6+:
- Secure - No embedded content is rendered, whether it's an image or an "object" (flash, quicktime, sounds, etc.)
- Insecure - All content is rendered.
- Workaround - Embedded images are rendered, but "objects" are not.
- is related to
-
JRASERVER-43916 Internet Explorer MIME Sniffing Security Hole Workaround Policy does not block PNG files
- Closed
-
JRASERVER-43914 Remove Internet Explorer MIME Sniffing Security Hole Workaround Policy
- Closed
- discovered while testing
-
JRADEV-12744 Loading...