Details

    • Business Value:
      4
    • Similar Issues:
      Show 4 results 

      Description

      Steps to reproduce:

      1-Add RSS portet
      2-Use a feed which titles type is HTML

      Result:
      The title is escaped.

        Activity

        Hide
        Tomas Polesovsky added a comment - - edited

        The title is escaped to prevent possible XSS (fixed in LPS-15678).

        I believe this is not a bug, because it was intended to escape HTML in entry titles.

        The problem there may be HTML/SGML entities (æ) that are not valid XML entities => they are escaped and will be displayed as escaped. The solution to fix this particular case could be:
        1, to use UTF-8 characters and don't use HTML entities in the source feed - æ => æ
        2, or sanitize ONLY the dangerous characters in the title (<>)
        3, or to provide an option in RSS feed portlet to disable title escaping

        Show
        Tomas Polesovsky added a comment - - edited The title is escaped to prevent possible XSS (fixed in LPS-15678 ). I believe this is not a bug, because it was intended to escape HTML in entry titles. The problem there may be HTML/SGML entities (æ) that are not valid XML entities => they are escaped and will be displayed as escaped. The solution to fix this particular case could be: 1, to use UTF-8 characters and don't use HTML entities in the source feed - &aelig; => æ 2, or sanitize ONLY the dangerous characters in the title (<>) 3, or to provide an option in RSS feed portlet to disable title escaping
        Hide
        Manuel de la Peña added a comment - - edited

        If the feed retrieves 'Ø' character (unescaped, instead of & Oslash), then is escaped properly.

        Moving to Feature Request as Tomas suggested.

        Show
        Manuel de la Peña added a comment - - edited If the feed retrieves 'Ø' character (unescaped, instead of & Oslash), then is escaped properly. Moving to Feature Request as Tomas suggested.

          People

          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Days since last comment:
              1 year, 47 weeks, 2 days ago

              Development

                Structure Helper Panel