-
Bug
-
Resolution: Fixed
-
Blocker
-
4.4.5
-
any
We figured out that a content operator (editor) can put javascript code to the activation dialog.
The JS code will be executed on the publisher inbox.
To avoid this, change the line (in class info.magnolia.module.workflow.inbox.Inbox):
============
list.addColumn(new ListColumn("comment", msgs.get("inbox.comment"), "200", true));
============
to the following:
============
list.addColumn(new ListColumn() {
@Override
public Object getValue()
});
============
Acceptance criteria