[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 --- Comment #5 from Platonides platoni...@gmail.com 2011-11-22 23:02:16 UTC --- We have code for CSS sanitizing in other parts of MediaWiki, the CSSMin class is able to remap and datify css urls... I'm not an expert with that part, but I think

[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 Rusty Burchfield gicodewarr...@gmail.com changed: What|Removed |Added Status|ASSIGNED|RESOLVED

[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 --- Comment #3 from Platonides platoni...@gmail.com 2011-11-20 22:32:43 UTC --- I don0t think goign through javascript would be needed. -- Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email --- You are receiving

[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 --- Comment #4 from Rusty Burchfield gicodewarr...@gmail.com 2011-11-20 22:51:54 UTC --- (In reply to comment #3) I don0t think goign through javascript would be needed. Care to elaborate? -- Configure bugmail:

[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-02 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 Rusty Burchfield gicodewarr...@gmail.com changed: What|Removed |Added AssignedTo|wikibugs-l@lists.wikimedia.

[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-02 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 Rusty Burchfield gicodewarr...@gmail.com changed: What|Removed |Added Status|NEW |ASSIGNED

[Bug 32154] Extension:CSS does not sanitize CSS from article pages

2011-11-02 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=32154 --- Comment #1 from Rusty Burchfield gicodewarr...@gmail.com 2011-11-03 02:59:21 UTC --- I also need to turn the inline styles into a link tag to eliminate any injection possibility there. -- Configure bugmail: