[wp-trac] Re: [WordPress Trac] #4789: Write Post title doesn't escape HTML tags

WordPress Trac wp-trac at lists.automattic.com
Mon Dec 31 21:52:54 GMT 2007


#4789: Write Post title doesn't escape HTML tags
----------------------------+-----------------------------------------------
 Reporter:  hje1555         |        Owner:  anonymous
     Type:  defect          |       Status:  reopened 
 Priority:  normal          |    Milestone:  2.4      
Component:  Administration  |      Version:  2.3.2    
 Severity:  normal          |   Resolution:           
 Keywords:                  |  
----------------------------+-----------------------------------------------
Changes (by DavidSzp):

  * status:  closed => reopened
  * resolution:  duplicate =>
  * version:  => 2.3.2
  * component:  General => Administration
  * milestone:  => 2.4

Comment:

 I wrote a post with the title "</2007>" for New Years Eve today. Instead,
 my post title turns up blank in the web browser. This is not expected
 behavior! It is not clear that HTML is acceptable and must be escaped in
 the title anywhere in the interface. I had to edit the post title to
 "&lt;/2007&gt;" manually, which fixed it, but I shouldn't have had to do
 that.

 Additionally, with the original title I specified above, the auto-
 generated post-slug was "176" which was the post ID of the post, not
 "2007" which is the expected, sanitized slug (I changed it to
 "closing-2007" manually, but it was still incorrect).

 I do agree that allowing a plugin to override this behavior if people want
 to use HTML in their titles is a good idea.

 I am re-opening this ticket as although it is marked duplicate, I can't
 find where the duplicate ticket is! I searched.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/4789#comment:9>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list