Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-28901

Make legacy ezhttp operator safer by default

    XMLWordPrintable

Details

    Description

      Can we make the ezhttp operator safer by default without breaking BC?

      The PR #1349 uses PHPs filter_var() to strip out tags, with FILTER_SANITIZE_STRING and FILTER_FLAG_STRIP_LOW|FILTER_FLAG_NO_ENCODE_QUOTES. Unsure if this is backwards compatible in every case, or whether it may break some sites.

      Input, reviews, and improvements are welcome!

      Attachments

        Activity

          People

            Unassigned Unassigned
            jacek.foremski-obsolete@ez.no Jacek Foremski (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: