https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=40659
--- Comment #13 from David Cook <[email protected]> --- (In reply to Lucas Gass (lukeg) from comment #12) > Is there any reason those details cannot be shared here fro transparency? Typically, we'd talk about it in the Koha Security project. I thought folks might like to keep this bug in Koha, but we could move it to Koha Security for a fuller discussion? > If scrubbing the HTML is the only issue then I think this should be left in > Notices/Slips where it can be scrubbed. The reason is simple, notices/slips > already has a pattern for using placeholder/substitutions which will be need > in this bug. I advocate to leave this in notice/slips for that reason. That's a compelling point. It does have a better UI for that for sure. What about translatability? I was thinking HTML Customizations would be better as people could add in custom labels for each of their different language interfaces? -- You are receiving this mail because: You are watching all bug changes. _______________________________________________ Koha-bugs mailing list [email protected] https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
