[wp-trac] Re: [WordPress Trac] #6642: kses should not allow multiple hyphens in comments

WordPress Trac wp-trac at lists.automattic.com
Wed Apr 9 13:29:55 GMT 2008


#6642: kses should not allow multiple hyphens in comments
-------------------------+--------------------------------------------------
 Reporter:  schiller     |        Owner:  anonymous
     Type:  defect       |       Status:  reopened 
 Priority:  normal       |    Milestone:  2.7      
Component:  General      |      Version:  2.5      
 Severity:  normal       |   Resolution:           
 Keywords:  needs-patch  |  
-------------------------+--------------------------------------------------
Changes (by Viper007Bond):

  * keywords:  xhtml, kses => needs-patch
  * status:  closed => reopened
  * version:  => 2.5
  * resolution:  worksforme =>
  * milestone:  => 2.7

Comment:

 Okay, well that's an entirely different issue. ;)

 Confirmed that no-access users can post HTML comments, something that they
 shouldn't be able to do IMO. It's specifically allowed in the code though,
 so then I guess we should just make sure it doesn't break validation.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/6642#comment:7>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list