You are here: Foswiki>Tasks Web>Item13966 (19 Mar 2016, GeorgeClark)Edit Attach

Item13966: Rendering engine fails with HTML comments in HTML tag values

Priority: Normal
Current State: Confirmed
Released In: n/a
Target Release: n/a
Applies To: Engine
Reported By: CrawfordCurrie
Waiting For:
Last Change By: GeorgeClark
View the output of this topic using "View Source" in the browser. You will see that the trailing > gets replaced with >

this is caused in the rendering enginine, between 341 and 356. A SMELL suggests this has been known about for a long time.

-- CrawfordCurrie - 18 Feb 2016

I'm going to demote this task to "normal" priority. I can't see blocking the next release over it. As you say, this has been in the code for a long time. From what I can tell from the logs, it was there on the import at the start of the project. So this cannot suddenly become a blocker now. As the comment goes on to say, this code assumes that any HTML tags internal to other HTML tags have been escaped.

+    # SMELL: this next fragment does not handle the case where HTML tags
+    # are embedded in the values provided to other tags. The only way to
+    # do this correctly is to parse the HTML (bleagh!). So we just assume
+    # they have been escaped.

-- GeorgeClark - 19 Mar 2016

ItemTemplate edit

Summary Rendering engine fails with HTML comments in HTML tag values
ReportedBy CrawfordCurrie
Codebase trunk
SVN Range
AppliesTo Engine
Priority Normal
CurrentState Confirmed
TargetRelease n/a
ReleasedIn n/a
Topic revision: r2 - 19 Mar 2016, GeorgeClark
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy