Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixed bug that allows XSS with the codepen embed. #1578

Merged
merged 1 commit into from Jan 17, 2019

Conversation

davefollett
Copy link
Contributor

What type of PR is this? (check all applicable)

  • Bug Fix

Description

Fixed bug that allows XSS with the codepen embed. See #1577 for full details.

Related Tickets & Documents

Resolves #1577

Mobile & Desktop Screenshots/Recordings (if there are UI changes)

Added to documentation?

  • no documentation needed

@pr-triage pr-triage bot added the PR: unreviewed bot applied label for PR's with no review label Jan 17, 2019
@davefollett
Copy link
Contributor Author

Note: This fix will not cause an exception to be thrown for the bad option, but it will ignore/not use it. I wanted to get a fix in right away.

Copy link
Contributor

@Zhao-Andy Zhao-Andy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great, thanks for catching this!

@pr-triage pr-triage bot added PR: reviewed-approved bot applied label for PR's where reviewer approves changes and removed PR: unreviewed bot applied label for PR's with no review labels Jan 17, 2019
@maestromac maestromac merged commit 6c571e8 into forem:master Jan 17, 2019
@pr-triage pr-triage bot added PR: merged bot applied label for PR's that are merged and removed PR: reviewed-approved bot applied label for PR's where reviewer approves changes labels Jan 17, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
PR: merged bot applied label for PR's that are merged
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants