ampersand on search text

2014-08-14 Thread Greg Huber
Glen, When I do a search containing and ampersand, roller does not show correctly the returned text. eg b&z actually returns :b&z which renders as b&z It should return b&z with no second ampersand for it to render correctly. Checking the method getTerm() it does a double escape, where t

Re: ampersand on search text

2014-08-14 Thread Glen Mazza
Hi Greg, that was done by Dave as part of this commit last August 13th: http://svn.apache.org/viewvc?view=revision&revision=151, which *may* have been part of the XSS security release Dave did the following November: http://rollerweblogger.org/project/entry/apache_roller_5_0_2. It may have

Re: simplify requiredWeblogPermissionActions() and requiredGlobalPermissionActions()?

2014-08-14 Thread Glen Mazza
Does anyone else on the team have a view? #5 below I'm no longer sure on so I'm withdrawing that proposal but feedback on #1-#4 below is most welcome. Glen On 08/13/2014 04:27 PM, Dave wrote: I don't see the need for this change and I would leave those permissions in place. They existed to s

Re: simplify requiredWeblogPermissionActions() and requiredGlobalPermissionActions()?

2014-08-14 Thread Greg Huber
Personally I would leave as is. Having multiple roles/authorities per action, is kind of useful if you want to extend roller. The overhead is also minimal compared with what struts does internally. On 14 August 2014 23:35, Glen Mazza wrote: > Does anyone else on the team have a view? #5 belo