Security issue: web console does not escape HTML

0 views
Skip to first unread message

g.m...@gmail.com

unread,
Jul 8, 2014, 4:36:31 AM7/8/14
to sta...@clarkparsia.com
Whenever I insert HTML code into my triples (as an object), and try to print them on the web console, it gets interpreted!!!

How come the code is not escaped? Is there any way (with an escaping sequence for instance) to prevent this, without changing all < into &lt; ?

Mike Grove

unread,
Jul 8, 2014, 6:33:38 AM7/8/14
to stardog
No, that's a bug, we'll fix that for the next release.  Thanks for reporting.

Cheers,

Mike


On Tue, Jul 8, 2014 at 4:36 AM, <g.m...@gmail.com> wrote:
Whenever I insert HTML code into my triples (as an object), and try to print them on the web console, it gets interpreted!!!

How come the code is not escaped? Is there any way (with an escaping sequence for instance) to prevent this, without changing all < into &lt; ?

--
-- --
You received this message because you are subscribed to the C&P "Stardog" group.
To post to this group, send email to sta...@clarkparsia.com
To unsubscribe from this group, send email to
stardog+u...@clarkparsia.com
For more options, visit this group at
http://groups.google.com/a/clarkparsia.com/group/stardog?hl=en

g.m...@gmail.com

unread,
Jul 8, 2014, 7:13:02 AM7/8/14
to sta...@clarkparsia.com
Any idea of when that release will come? What about the other bug-fix (max password length), was it fixed in 2.2?

Mike Grove

unread,
Jul 8, 2014, 7:33:36 AM7/8/14
to stardog
On Tue, Jul 8, 2014 at 7:13 AM, <g.m...@gmail.com> wrote:
Any idea of when that release will come? What about the other bug-fix (max password length), was it fixed in 2.2?

Yes, that was fixed in 2.2.

Cheers,

Mike
Reply all
Reply to author
Forward
0 new messages