jenkins-bot has submitted this change and it was merged.

Change subject: Sanitize embed HTML
......................................................................


Sanitize embed HTML

Make sure tables, lists and other complex stuff do not get into the
embed HTML code.

Change-Id: I559dc7892e058e403ddde6994a7e1ac0c9585325
Mingle: https://wikimedia.mingle.thoughtworks.com/projects/multimedia/cards/369
---
M resources/mmv/mmv.EmbedFileFormatter.js
1 file changed, 3 insertions(+), 0 deletions(-)

Approvals:
  Gilles: Looks good to me, approved
  jenkins-bot: Verified



diff --git a/resources/mmv/mmv.EmbedFileFormatter.js 
b/resources/mmv/mmv.EmbedFileFormatter.js
index 9181690..93766e3 100644
--- a/resources/mmv/mmv.EmbedFileFormatter.js
+++ b/resources/mmv/mmv.EmbedFileFormatter.js
@@ -76,6 +76,9 @@
         * @return {string} byline (can contain HTML)
         */
        EFFP.getByline = function ( author, source ) {
+               author = author && this.htmlUtils.htmlToTextWithLinks( author );
+               source = source && this.htmlUtils.htmlToTextWithLinks( source );
+
                if ( author && source) {
                        return mw.message(
                                'multimediaviewer-credit',

-- 
To view, visit https://gerrit.wikimedia.org/r/120953
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: merged
Gerrit-Change-Id: I559dc7892e058e403ddde6994a7e1ac0c9585325
Gerrit-PatchSet: 7
Gerrit-Project: mediawiki/extensions/MultimediaViewer
Gerrit-Branch: master
Gerrit-Owner: Gergő Tisza <gti...@wikimedia.org>
Gerrit-Reviewer: Gergő Tisza <gti...@wikimedia.org>
Gerrit-Reviewer: Gilles <gdu...@wikimedia.org>
Gerrit-Reviewer: jenkins-bot <>

_______________________________________________
MediaWiki-commits mailing list
MediaWiki-commits@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to