[ 
https://issues.apache.org/jira/browse/OFBIZ-12653?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17556836#comment-17556836
 ] 

Ingo Wolfmayr commented on OFBIZ-12653:
---------------------------------------

This is the tag, created by Trumbowyg:  <img 
src="https://www.wolfix.at/logo.png"; alt="Test"> and fails with Sanitizer.

<img src="https://www.wolfix.at/logo.png"; alt="Test" /> would be ok.

I have downloaded the source and I am looking forward to provide a patch on 
Trumbowyg side. I think the issue is fixed, when the correct data is provided 
to the sanitizer. Lets see if the community there is still alive.

 

> Sanitizer <br> fail
> -------------------
>
>                 Key: OFBIZ-12653
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-12653
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: content
>    Affects Versions: Upcoming Branch
>            Reporter: Ingo Wolfmayr
>            Assignee: Jacques Le Roux
>            Priority: Major
>
> I copied a text with multiple lines from a text editor into the Trumbowyg 
> Html field.The editor creates the Html structure using unclosed <br> elements.
> Unfortunately the sanitizer logic just takes <br />. A security warning is 
> thrown and the content will not be stored.
> Issue also a request on Trumbowyg request list:
> [https://github.com/Alex-D/Trumbowyg/issues/1283]



--
This message was sent by Atlassian Jira
(v8.20.7#820007)

Reply via email to