Uploaded image for project: 'Magnolia Standard Templating Kit (closed)'
  1. Magnolia Standard Templating Kit (closed)
  2. MGNLSTK-1103

Wrap nodes with HTMLEscapingNodeWrapper before rendering - port to master

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Major Major
    • 2.5
    • None
    • None
    • None

      MAGNOLIA-4011 introduces unwrapping nodes before rendering because of problem with multiple escaping.
      Unfortunately This change causes XSS vulnerability of most FTL templates.

      1. Don't unwrap nodes from HTMLEscapingNodeWrapper before rendering.
      2. Wrap nodes with HTMLEscapingNodeWrapper if they are not wrapped already.

        Acceptance criteria

              rkovarik Roman Kovařík
              rkovarik Roman Kovařík
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: