NPM Resource Changed ? ? ? Pending

User tests: Successful: Unsuccessful:

avatar dgrammatiko
dgrammatiko
9 Jun 2021

Pull Request for Issue # .

This is also a RELEASE BLOCKER

Summary of Changes

  • sanitize the iframe tag passed as a data attribute

Testing Instructions

Apply the patch or download the installable package from the Github PR

Try to edit an article, select an image, select a user
Try to edit a menu item and create/edit an article
Modals should work fine

Actual result BEFORE applying this Pull Request

The initialization of a modal could be compromised to run non verified code

Expected result AFTER applying this Pull Request

The iframe tag can not be compromised

Documentation Changes Required

avatar dgrammatiko dgrammatiko - open - 9 Jun 2021
avatar dgrammatiko dgrammatiko - change - 9 Jun 2021
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 9 Jun 2021
Category JavaScript Repository NPM Change
avatar dgrammatiko dgrammatiko - change - 9 Jun 2021
Labels Added: NPM Resource Changed ? ?
avatar sandramay0905 sandramay0905 - test_item - 10 Jun 2021 - Tested successfully
avatar sandramay0905
sandramay0905 - comment - 10 Jun 2021

I have tested this item successfully on ea7b59a

Test was:

  • Create a new article, append image in article text, select user. Save, view in back- and frontend. Use Codemirror.
  • Create new menu-item Single article, create article, save menu-item, view in front end. Reopen menu-item, edit article, save and view in frontend again.
    This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/34480.
avatar jwaisner jwaisner - test_item - 10 Jun 2021 - Tested successfully
avatar jwaisner
jwaisner - comment - 10 Jun 2021

I have tested this item successfully on ea7b59a


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/34480.

avatar jwaisner jwaisner - change - 10 Jun 2021
Status Pending Ready to Commit
avatar jwaisner
jwaisner - comment - 10 Jun 2021

RTC


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/34480.

avatar richard67 richard67 - change - 12 Jun 2021
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2021-06-12 12:45:15
Closed_By richard67
Labels Added: ? ?
Removed: ?
avatar richard67 richard67 - close - 12 Jun 2021
avatar richard67 richard67 - merge - 12 Jun 2021
avatar richard67
richard67 - comment - 12 Jun 2021

Thanks!

Add a Comment

Login with GitHub to post a comment