https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=40659

--- Comment #13 from David Cook <[email protected]> ---
(In reply to Lucas Gass (lukeg) from comment #12)
> Is there any reason those details cannot be shared here fro transparency? 

Typically, we'd talk about it in the Koha Security project. I thought folks
might like to keep this bug in Koha, but we could move it to Koha Security for
a fuller discussion?

> If scrubbing the HTML is the only issue then I think this should be left in
> Notices/Slips where it can be scrubbed. The reason is simple, notices/slips
> already has a pattern for using placeholder/substitutions which will be need
> in this bug. I advocate to leave this in notice/slips for that reason.

That's a compelling point. It does have a better UI for that for sure. 

What about translatability? I was thinking HTML Customizations would be better
as people could add in custom labels for each of their different language
interfaces?

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list
[email protected]
https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to