Item9412: taint error ("web is tainted") when using ?skin param

pencil
Priority: Urgent
Current State: Closed
Released In: 1.1.0
Target Release: minor
Applies To: Engine
Component:
Branches:
Reported By: PaulHarvey
Waiting For:
Last Change By: CrawfordCurrie
Eg. http://trunk.foswiki.org/Tasks/Item9412?skin=pattern

Seems to only affect view

Assertion (web is tainted) failed!
 at /usr/home/trunk.foswiki.org/core/lib/Assert.pm line 78
   Assert::ASSERT('undef', 'web is tainted') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki.pm line 3555
   Foswiki::topicExists('Foswiki=HASH(0xe37728)', 'Tasks', 'PatternSkinViewtopicactionbuttonsTemplate') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/Templates.pm line 436
   Foswiki::Templates::_readTemplateFile('Foswiki::Templates=HASH(0x153da28)', 'undef', 'pattern', 'Tasks') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/Templates.pm line 238
   Foswiki::Templates::readTemplate('Foswiki::Templates=HASH(0x153da28)', 'view', 'no_oops', 1) called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI/View.pm line 226
   Foswiki::UI::View::view('Foswiki=HASH(0xe37728)') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI.pm line 310
   Foswiki::UI::__ANON__() called at /usr/local/lib/perl5/site_perl/5.8.8/Error.pm line 415
   eval {...} called at /usr/local/lib/perl5/site_perl/5.8.8/Error.pm line 407
   Error::subs::try('CODE(0xdbcba8)', 'HASH(0xe37418)') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI.pm line 429
   Foswiki::UI::_execute('Foswiki::Request=HASH(0xdedcc8)', 'CODE(0xded888)', 'view', 1) called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI.pm line 277
   Foswiki::UI::handleRequest('Foswiki::Request=HASH(0xdedcc8)') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/Engine/CGI.pm line 30
   Foswiki::Engine::CGI::run('Foswiki::Engine::CGI=HASH(0x8d71f8)') called at /home/trunk.foswiki.org/core/bin/view line 24
 at /usr/home/trunk.foswiki.org/core/lib/Assert.pm line 78
   Assert::ASSERT('undef', 'web is tainted') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki.pm line 3555
   Foswiki::topicExists('Foswiki=HASH(0xe37728)', 'Tasks', 'PatternSkinViewtopicactionbuttonsTemplate') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/Templates.pm line 436
   Foswiki::Templates::_readTemplateFile('Foswiki::Templates=HASH(0x153da28)', 'undef', 'pattern', 'Tasks') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/Templates.pm line 238
   Foswiki::Templates::readTemplate('Foswiki::Templates=HASH(0x153da28)', 'view', 'no_oops', 1) called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI/View.pm line 226
   Foswiki::UI::View::view('Foswiki=HASH(0xe37728)') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI.pm line 310
   Foswiki::UI::__ANON__() called at /usr/local/lib/perl5/site_perl/5.8.8/Error.pm line 415
   eval {...} called at /usr/local/lib/perl5/site_perl/5.8.8/Error.pm line 407
   Error::subs::try('CODE(0xdbcba8)', 'HASH(0xe37418)') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI.pm line 429
   Foswiki::UI::_execute('Foswiki::Request=HASH(0xdedcc8)', 'CODE(0xded888)', 'view', 1) called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/UI.pm line 277
   Foswiki::UI::handleRequest('Foswiki::Request=HASH(0xdedcc8)') called at /usr/home/trunk.foswiki.org/core/lib/Foswiki/Engine/CGI.pm line 30
   Foswiki::Engine::CGI::run('Foswiki::Engine::CGI=HASH(0x8d71f8)') called at /home/trunk.foswiki.org/core/bin/view line 24.

-- PaulHarvey - 30 Jul 2010

Nasty. Skin name validation was (still) SNAFU.

-- CrawfordCurrie - 30 Jul 2010

 

ItemTemplate edit

Summary taint error ("web is tainted") when using ?skin param
ReportedBy PaulHarvey
Codebase trunk
SVN Range
AppliesTo Engine
Component
Priority Urgent
CurrentState Closed
WaitingFor
Checkins distro:8fb73382f24e
TargetRelease minor
ReleasedIn 1.1.0
Topic revision: r3 - 30 Jul 2010, CrawfordCurrie
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy