Stripping CDATA blocks from JS

6 views
Skip to first unread message

sephr

unread,
Nov 11, 2009, 5:35:30 PM11/11/09
to mozilla-labs-jetpack
It seems with most recent update of the Jetpack Gallery, a CDATA block
literal was removed from my GTranslatifier Jetpack. I would like to
know if this was intentional (trying to remove exploits from
submissions?) or unintentional as to know if it will happen again. The
CDATA block literal contained a base64-encoded data: URI for the
status bar icon of the Jetpack.

sephr

unread,
Nov 11, 2009, 6:11:31 PM11/11/09
to mozilla-labs-jetpack
Nevermind, it seems it was an error with me updating the Jetpack and
not re-pasting the code into the Bespin editor. Bespin strips the
CDATA block every time the code is loaded.

Christian Sonne

unread,
Nov 11, 2009, 6:54:56 PM11/11/09
to mozilla-la...@googlegroups.com
I am pretty sure I know the cause of this, and I have notified the author of the gallery via twitter. I'll report back with updates.

Best regards
-- cers / Christian Sonne

Aza

unread,
Nov 11, 2009, 9:56:10 PM11/11/09
to mozilla-la...@googlegroups.com
Christian, better would be to file a bug :)

On Wednesday, November 11, 2009, Christian Sonne <frea...@gmail.com> wrote:
> I am pretty sure I know the cause of this, and I have notified the author of the gallery via twitter. I'll report back with updates.
>
> Best regards-- cers / Christian Sonne
>
>
> On Thu, Nov 12, 2009 at 12:11 AM, sephr <eli...@grey.name <javascript:_e({}, 'cvml', 'eli...@grey.name');>> wrote:
>
>
> Nevermind, it seems it was an error with me updating the Jetpack and
> not re-pasting the code into the Bespin editor. Bespin strips the
> CDATA block every time the code is loaded.
>
> On Nov 11, 5:35 pm, sephr <eli...@grey.name <javascript:_e({}, 'cvml', 'eli...@grey.name');>> wrote:
>> It seems with most recent update of the Jetpack Gallery, a CDATA block
>> literal was removed from my GTranslatifier Jetpack. I would like to
>> know if this was intentional (trying to remove exploits from
>> submissions?) or unintentional as to know if it will happen again. The
>> CDATA block literal contained a base64-encoded data: URI for the
>> status bar icon of the Jetpack.
>
> >
>

--
-- aza | ɐzɐ --

Christian Sonne

unread,
Nov 11, 2009, 10:08:06 PM11/11/09
to mozilla-la...@googlegroups.com
Wasn't sure if I should file it under Jetpack or if the gallery had it's own component or even it's own issue tracker.

However, Ryan filled out a bug in bugzilla
https://bugzilla.mozilla.org/show_bug.cgi?id=528074


-- cers / Christian Sonne


Changjian Gao

unread,
Nov 11, 2009, 10:55:14 PM11/11/09
to mozilla-la...@googlegroups.com
I have encountered this error too. This is my bugzilla report: https://bugzilla.mozilla.org/show_bug.cgi?id=527906

Aza

unread,
Nov 16, 2009, 5:47:32 AM11/16/09
to mozilla-la...@googlegroups.com
This should be fixed now.

-- aza | ɐzɐ --
Reply all
Reply to author
Forward
0 new messages