Project

General

Profile

Actions

Bug #20846

closed

Synchronize RemoveXSS.php in 4.2 and 4.3

Added by Steffen Kamper over 15 years ago. Updated over 14 years ago.

Status:
Closed
Priority:
Should have
Category:
-
Target version:
-
Start date:
2009-08-07
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.3
PHP Version:
5.3
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

This file is used for security reasons. So it's important to have all fixes not only in 4.3 but in 4.2. For this reason both files should be identical.

(issue imported from #M11664)


Files

Actions #1

Updated by Marcus Krause over 15 years ago

No objections.

Actions #2

Updated by Steffen Kamper about 15 years ago

The uploaded patch is the version used in trunk. So we have the same security for RemoveXSS in both versions (4.2 and trunk)

Ernesto, please add to your reviews for beta2

Actions #3

Updated by Ernesto Baschny about 15 years ago

Steffen, will do.

First note is that I would love to see some unit tests for the most common XSS cases that are being handled by this script, so that we can make sure it doesn't break if we change something. The function is pretty long and tedious to test or consider all potential exploits.

Actions #4

Updated by Steffen Kamper about 15 years ago

Ernesto, i will start with unit tests in trunk.
I did a page where i compared the "new" file (this) against the old (4.2 current) here:
http://www.sk-typo3.de/index.php?id=370

Actions #5

Updated by Steffen Kamper about 15 years ago

I also installed a testscript here:
http://www.sk-typo3.de/RemoveXSS.376.0.html

Actions #6

Updated by Steffen Kamper about 15 years ago

added some unit tests in #21314 - will commit it to trunk in some minutes

Actions #7

Updated by Ernesto Baschny about 15 years ago

Steffen, thanks a lot for the work. I haven't reviewed it but I assume it is already ok. Have you commited it? "Some minutes" have already passed. :)

Actions #8

Updated by Steffen Kamper about 15 years ago

it's committed yesterday to trunk (unit tests). This patch is for 4_2 and should go to 4.2.10 so we have the same file in both versions for better maintainance (i promised Larsto tke care)

Actions #9

Updated by Ernesto Baschny about 15 years ago

Ok Steffen, thanks! I will review this and we will commit this right before release of 4.2.10 (meaning tomorrow morning).

Actions #10

Updated by Ernesto Baschny about 15 years ago

Commited to TYPO3_4-2, rev.6228

Actions #11

Updated by Ernesto Baschny about 15 years ago

reopened to make it public

Actions

Also available in: Atom PDF