Re: [Mediawiki-l] div style = "/* insecure input */"

2011-04-28 Thread Tim Starling
On 29/04/11 04:50, Brion Vibber wrote: > But that's not why it's being stripped: various little CSS extensions like > 'expression', xbl bindings, and IE's 'filter's are potentially unsafe, > though it's unclear to me at the moment exactly how dangerous the filters > are as I haven't looked at it in

Re: [Mediawiki-l] div style = "/* insecure input */"

2011-04-28 Thread Brion Vibber
On Thu, Apr 28, 2011 at 11:29 AM, Dan Nessett wrote: > When I inspect the output html at the browser, the output div is: > > > When I remove "filter:alpha(opacity=99);" from the link text, things work > fine (at least on FF and Safari). Investigating, it seems the > "filter:alpha(opacity=99);" a

[Mediawiki-l] div style = "/* insecure input */"

2011-04-28 Thread Dan Nessett
Our wiki has a template that displays a mini-periodical table. Each table entry is represented by a small box, which is a link to the corresponding element's page. When we upgraded to 1.16.2, this template stopped working. I have traced the problem to some html added as link text. Specifically,