Disallow HTML in custom field descriptions and list item values by default

XMLWordPrintable

    • 1

      Problem

      By default, Jira allows HTML in custom field descriptions and list item values. The configuration item that prevents this is in Jira Admin -> System -> Enable HTML in custom field descriptions and list item values, and is is Enabled by default.

      Justification

      This introduces scope for values to break the page in exciting ways - for example, adding <!-- break the rest of the page when the field is loaded. Actually, on Field Configuration and Custom Fields pages, this prevents the ability to edit to undo the breakage (aside from editing the database)

      Some customers require this, but, we should encourage it's disablement. Disabling it by default would help.

      Suggested Solution

      Disable this option by default

      from https://confluence.atlassian.com/jirasoftware/jira-software-8-7-x-upgrade-notes-987138245.html

      ... It will now be switched to OFF for new Jira installations and the upgraded ones that have never used it. ... We recommend that you keep this option disabled for security reasons.

            Assignee:
            Daniel Rauf
            Reporter:
            Alex [Atlassian,PSE]
            Votes:
            1 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved: