[wp-trac] [WordPress Trac] #24775: Revisions: Make sure our templating is properly escaped

WordPress Trac noreply at wordpress.org
Mon Jul 22 21:28:38 UTC 2013


#24775: Revisions: Make sure our templating is properly escaped
----------------------------+--------------------------
 Reporter:  markjaquith     |       Owner:  markjaquith
     Type:  task (blessed)  |      Status:  closed
 Priority:  normal          |   Milestone:  3.6
Component:  Security        |     Version:  trunk
 Severity:  normal          |  Resolution:  fixed
 Keywords:                  |
----------------------------+--------------------------

Comment (by rmccue):

 Replying to [comment:2 nacin]:
 > I think {{{ to {{ for restoreUrl requires us to undo & => & that is
 done by wp_nonce_url()? I can't tell if it just accidentally works, or if
 {{ deliberately doesn't re-escape &

 Looks like `{{` should reescape everything, based on
 [http://underscorejs.org/docs/underscore.html#section-129 the source].

--
Ticket URL: <http://core.trac.wordpress.org/ticket/24775#comment:5>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list