HTML not escaped in Deployment script output in 5.2.0

3 views
Skip to first unread message

Alexander Obuhovich

unread,
May 16, 2012, 9:28:04 AM5/16/12
to In-Portal Bugs
In In-Portal 5.1.3 we've introduced deployment script, that allows to automatically deploy changes made by developers on staging and production servers with ease.

In In-Portal 5.2.0-B1 it was improved to include deployment output also on "System Tools" page, when "Deploy" or "Synchronize" buttons were pressed.
However in 5.2.0-B3 I've found that we don't escape HTML in script output when output goes to browser.


Ready for testing.

--
Best Regards,

http://www.in-portal.com
http://www.alex-time.com
deplyment_script_doesnt_escape_html.patch
Reply all
Reply to author
Forward
0 new messages